Loading prices…
🩸BEARISH

Coldcard flaw drains 594 BTC from 500 wallets in 25 minutes

The single-signature wallets swept had been dormant for years, but the underlying firmware bug has been live since March 2021, with paper wallet keys and seed-splitting masks exposed too.

Coldcard flaw drains 594 BTC from 500 wallets in 25 minutes
Coldcard flaw drains 594 BTC from 500 wallets in 25 minutes
Coldcard flaw drains 594 BTC from 500 wallets in 25 minutes
Coldcard flaw drains 594 BTC from 500 wallets in 25 minutes

Roughly 594 bitcoin, worth about $38 million, was siphoned out of around 500 single-signature wallets between 01:31 and 01:56 UTC on Friday in a 25-minute sweep traced to a key-generation flaw in Coldcard hardware wallets. The drain moved 1,324 chunks of bitcoin across 500 transactions inside a three-block window, with 562 BTC then consolidated into a single address that has yet to move. Every drained wallet held more than 0.15 BTC, and many had been dormant for years, with coins spanning 2021 to 2026, a range that matches the age of the vulnerability almost exactly.

The flaw sits in Coldcard firmware 4.0.0, shipped in March 2021. A build setting told the device to skip its hardware randomness generator, and a check in a supporting library tested only whether that setting existed rather than whether it was switched on. Key generation quietly fell through to a basic software substitute seeded from the chip's serial number and clock registers, neither of which are secrets. The serial number is fixed factory metadata, and the clock values are timing state an attacker can narrow down or measure on a device of their own. Block's Bitcoin engineering and security teams traced the change to a commit dated March 1, 2021 and attributed the theft to that bug.

Why it matters

Coldcard is built by Canadian firm Coinkite as a small standalone device that stores bitcoin keys offline, away from internet-connected computers. The exposure is product-generation specific: Coinkite has warned users who generated a seed on an Mk3 running firmware 4.0.1 or later, while stressing that Mk4, Q and Mk5 appear unaffected so far. The risk does not stop at wallet seeds. The same generator produced Coldcard's paper wallet private keys, where the output becomes the key directly with no further derivation, along with seed-splitting masks, device cloning keys and Key Teleport transfers, all of which inherit the same predictability. Block disclosed its findings to Coinkite, whose team acknowledged them, and both companies describe their analyses as preliminary.

Related tokens
$BTC

Frequently asked questions

  1. Which Coldcard devices are affected by the key-generation flaw?

    Coinkite warned users who generated a seed on an Mk3 running firmware 4.0.1 or later. The company said Mk4, Q and Mk5 are not affected based on its early analysis.

  2. How did the attacker exploit the vulnerability?

    A build setting in firmware 4.0.0 told the device to skip its hardware randomness generator, and key generation fell through to a software substitute seeded from the chip's serial number and clock registers, neither of which are secrets.

  3. How much bitcoin was stolen and over what time window?

    Roughly 594 BTC, worth about $38 million, was swept out of around 500 single-signature wallets between 01:31 and 01:56 UTC on Friday, moving 1,324 chunks across 500 transactions in a three-block window.

  4. Does the exposure extend beyond wallet seed phrases?

    Yes. The same generator produced Coldcard's paper wallet private keys, where the output becomes the key directly with no further derivation, plus seed-splitting masks, device cloning keys and Key Teleport transfers, all of which inherit the same predictability.

  5. Did the theft move bitcoin's price?

    Bitcoin traded above $64,000 in early Asian hours, with the widespread drain having little visible impact on market price, reflecting the wallet's narrower self-custody user base.

Source attribution
Aggregated from CoinDesk · Verified · Last refreshed 1h ago
Open original →