Bitcoin Magazine

Coldcard Wallet Flaw Exposes Years of Bitcoin Seeds After $70M in BTC Stolen
The popular Bitcoin hardware wallet Coldcard product, made by Coinkite, is at risk following a $70 million hack.
Coinkite on Thursday admitted that its Coldcard Mk3 model was affected following the hack and advised users to move their funds. Then, on Friday, the company said that users of the later hardware devices Mk4, Mk5, and Q should also take precautions.
Hackers on Thursday were first able to drain funds from 1,196 Bitcoin addresses because their private keys were not generated using sufficient entropy — or randomness.
Since then, a total of 1,082.65 Bitcoins have disappeared from wallets, according to data from Galaxy Research and engineers at payments company Block.
While Coinkite has not admitted that the hack is linked to their wallets, the company has said that a wallet seed generation bug in Coldcard products meant the hardware’s true random number generator wasn’t actually being used on certain firmware versions.
Coinkite and other engineers in the Bitcoin space are still investigating reportedly ongoing drains still happening at the time of writing.
What actually happened
A firmware bug in Coldcard Mk3 devices (starting with version 4.0.1 in March 2021) caused seed generation to fall back to a weak software PRNG instead of the hardware true random number generator, producing seeds with only ~40 bits of entropy rather than the intended 128. This made private keys for many single-signature wallets (especially those created without dice rolls or a strong BIP-39 passphrase) predictable enough for attackers to brute-force.
A total of 594.5 Bitcoins worth over $35.7 million at today’s prices were moved to a new address from single-signature addresses on Thursday.
More wallets were later drained, according to blockchain analysts, with the total now over $70 million.
Various affected users shared their experiences on social media, with one saying that their Bitcoin had not been moved since 2021, and all of a sudden was swiped.
Bitcoin engineers have since said that Coldcard products — specifically the Mk3 models — had “faulty entropy in wallet generation,” meaning they did not use real randomness to create a seedphrase.
What to do
Developers in the Bitcoin space have since urged users to move their funds if they used a Coldcard. Coldcard has issued guidance for users to take, which can be found here.
Coinkite first said that their Mk3 models were affected but then on Friday said that those who did not use sufficient entropy to create a seed — in this case, 50 dice rolls — should generate a brand-new seed on the updated device. Others have warned to ditch Coldcard completely to be sure their funds are safe.
“Everything is fucked,” wrote Kevin Loaec, CEO of Bitcoin security company, Wizardsardine.
“Every single mnemonic generated [via a Coldcard] since 2021 will be public in the next few days,” Loaec warns.
This post Coldcard Wallet Flaw Exposes Years of Bitcoin Seeds After $70M in BTC Stolen first appeared on Bitcoin Magazine and is written by Mathew Di Salvo.


NEW: Over 594 BTC worth $38 million was stolen from Bitcoin hardware wallet Coldcard users.












Lämna ett svar