Key facts
- Losses from the Coldcard Bitcoin hack have surpassed $114 million, with potential to reach $130 million.
- The exploit stems from a firmware flaw in Coldcard Mk2 and Mk3 models, specifically version 4.0.1 released around March 2021.
- The flaw caused wallets to use a weaker pseudorandom number generator for seed creation, making private keys easier to guess.
- Attackers swept funds from vulnerable wallets without physical access to the devices.
- Galaxy Research confirmed 1,596 BTC stolen across approximately 7,300 addresses in multiple waves.
- Coinkite has released patched firmware, but users who generated seeds on vulnerable versions must move their funds immediately.
Losses from a hack targeting Coldcard Bitcoin hardware wallets have escalated significantly, now exceeding $114 million and potentially reaching $130 million, according to Galaxy Research. The exploit is attributed to a five-year-old firmware flaw in version 4.0.1, released around March 2021, which affected Coldcard Mk2 and Mk3 models. This bug caused the wallets to improperly use a hardware true random number generator, falling back to a weaker software-based pseudorandom number generator that reduced effective entropy to as low as 40 bits. Attackers were able to pre-compute candidate seeds, match them to on-chain addresses, and sweep single-signature wallets without physical access. Galaxy Research has confirmed 1,596 BTC stolen across approximately 7,300 addresses in multiple waves, with about 90% of the funds remaining unmoved. Coinkite has released patched firmware, but strongly advises users who generated seeds on vulnerable builds to move their funds immediately to a newly created wallet. Ripple CTO Emeritus David Schwartz drew comparisons to historical traditional finance failures, highlighting the current lack of insurance for self-custody crypto losses and renewing debate on hardware wallet security.
