Key facts
- A flaw in Coldcard hardware wallets led to the theft of approximately 594 bitcoin.
- The stolen bitcoin is valued at $38 million.
- The exploit affected about 500 single-signature wallets.
A significant flaw in Coldcard hardware wallets has led to the theft of approximately 594 bitcoin, valued at $38 million. The vulnerability, present in firmware version 4.0.0 released in March 2021, allowed attackers to use predictable software-based key generation instead of secure hardware randomness. This exploit reportedly affected around 500 single-signature wallets and was executed in a rapid 25-minute sweep. Coinkite has issued a warning to Coldcard Mk3 users, advising them to move their funds due to this potential seed risk.

A critical vulnerability in Coldcard hardware wallets has resulted in the theft of approximately 594 bitcoin, with an estimated value of $38 million. The exploit targeted about 500 single-signature wallets and was executed within a 25-minute timeframe. Security researchers identified that the flaw was introduced in firmware version 4.0.0, which was released in March 2021. This firmware update caused Coldcard devices to utilize predictable software-based key generation methods rather than relying on secure hardware randomness for generating cryptographic keys.
Coinkite, the company behind Coldcard, has alerted users of the Coldcard Mk3 model about a potential risk associated with seed generation. The company is urging affected users to migrate their funds to safer wallets as a precautionary measure. The rapid nature of the theft, occurring in under 30 minutes, suggests a sophisticated attack that leveraged the identified firmware weakness. The investigation into the $38 million Bitcoin wallet drain is ongoing, with a focus on how the predictable key generation was exploited.
The vulnerability lies in the core security mechanism of hardware wallets, which are designed to protect private keys from software-based attacks. By using predictable, software-generated keys, the security of the Coldcard devices was compromised, allowing an attacker to potentially derive the private keys and access the funds stored in the affected single-signature wallets. This incident highlights the importance of secure random number generation in cryptographic applications and the potential impact of even subtle flaws in firmware updates.
A critical vulnerability in Coldcard hardware wallets has resulted in the theft of approximately 594 bitcoin, with an estimated value of $38 million. The exploit targeted about 500 single-signature wallets and was executed within a 25-minute timeframe. Security researchers identified that the flaw was introduced in firmware version 4.0.0, which was released in March 2021. This firmware update caused Coldcard devices to utilize predictable software-based key generation methods rather than relying on secure hardware randomness for generating cryptographic keys.