A significant vulnerability in Coldcard's seed generation code has resulted in the theft of over $100 million in Bitcoin from thousands of users. The flaw, which went unnoticed for years, affected how wallet secrets were created, not the hardware's core functionality. This incident highlights ongoing security risks for cryptocurrency hardware wallet owners, as separate data breaches at shipping partners of Trezor and SafePal have exposed customer personal information, potentially leading to physical "wrench attacks."
✉Newsletter
PiQ Daily
Pick your topics. Get only what matters, on your cadence.
Key Numbers
$100MBitcoin stolen from Coldcard users
$130MBitcoin stolen via Coinkite Coldcard vulnerability
Who's Involved
Coldcard
crypto hardware wallet with a seed generation vulnerability
Trezor
crypto hardware wallet maker with exposed customer data
SafePal
crypto hardware wallet maker with exposed customer data
Coinkite
manufacturer of the Coldcard wallet
1 / 2
Key facts
A flaw in Coldcard's seed generation code allowed attackers to steal Bitcoin.
Over $100 million in Bitcoin was stolen due to the Coldcard vulnerability.
Thousands of users were affected by the Coldcard exploit.
The vulnerability was in the wallet's secrets generation, not the hardware itself.
Data breaches occurred at shipping partners of Trezor and SafePal.
Customer personal information was exposed in the Trezor and SafePal shipping partner breaches.
Exposed data increases the risk of physical "wrench attacks" for Trezor and SafePal customers.
Hackers stole over $130 million by exploiting a vulnerability in Coinkite's Coldcard wallet.
A critical bug within Coldcard's seed generation code has led to the theft of over $100 million in Bitcoin from thousands of users. This vulnerability, which remained undetected for several years, impacted the process by which the wallet's secrets were created, rather than any inherent flaw in the hardware itself. The exploit allowed attackers to compromise user funds, with the total amount stolen exceeding $100 million.
This incident underscores the broader security challenges faced by owners of cryptocurrency hardware wallets. In a separate development, data breaches have occurred at shipping partners for both Trezor and SafePal. These breaches have exposed sensitive customer personal information, raising concerns about the potential for physical "wrench attacks" against users. Additionally, hackers exploited a vulnerability in Coinkite's Coldcard wallet, leading to the theft of over $130 million.
The Coldcard vulnerability specifically relates to its seed generation process, a fundamental aspect of cryptocurrency wallet security. The fact that this flaw persisted for years without detection points to potential weaknesses in the software development and auditing processes of hardware wallet manufacturers. The scale of the theft, exceeding $100 million, represents a substantial loss for affected users and a significant security incident for the cryptocurrency industry.
↳ Why This Matters
A critical bug within Coldcard's seed generation code has led to the theft of over $100 million in Bitcoin from thousands of users. This vulnerability, which remained undetected for several years, impacted the process by which the wallet's secrets were created, rather than any inherent flaw in the hardware itself. The exploit allowed attackers to compromise user funds, with the total amount stolen exceeding $100 million.
Frequently asked questions
A seed phrase, also known as a recovery phrase or mnemonic phrase, is a list of words that can be used to recover your cryptocurrency wallet if you lose access to your device or forget your password.
A configuration error caused the Coldcard wallet to use a less secure software generator for randomness when creating seed phrases, rather than its intended hardware random number generator. This made the seed phrases predictable and guessable by attackers.
An air-gapped system is a computer or device that is physically isolated from unsecured networks, such as the internet. This is a key security feature for hardware wallets.
Users should monitor for firmware updates from Coinkite and apply any patches released to address the vulnerability. It is also advisable to review security practices and consider the implications of this breach.
What Happens Next
01Coinkite is expected to release a patch for the vulnerability.
02Users are advised to update their Coldcard firmware once a fix is available.
03Further audits of hardware wallet seed generation processes may be initiated.
Get the newsletter.
Pick the topics you actually care about. We'll email when there's news worth your time, on the cadence you choose. Cancel any time from your account.