Coldcard Firmware Error Linked to $70 Million Bitcoin Sweep
A firmware vulnerability in certain Coldcard hardware wallets has been linked to the theft of 1,082.65 bitcoin, worth approximately $70.2 million when the incident occurred. Galaxy Research said an at...
A firmware vulnerability in certain Coldcard hardware wallets has been linked to the theft of 1,082.65 bitcoin, worth approximately $70.2 million when the incident occurred. Galaxy Research said an attacker swept 1,196 addresses within about 41 minutes on July 30.
The issue originated in a March 2021 firmware integration error that caused affected devices to generate wallet seeds with MicroPython’s deterministic Yasmarang pseudorandom number generator rather than the STM32 chip’s hardware random-number source. According to Block, an attacker who could infer or narrow information such as a device identifier, timer state and previous random-number calls might reproduce possible output sequences offline. Those candidates could then be tested against publicly visible blockchain addresses.
Block traced the problem to a production configuration setting and a library check that treated a disabled random-number option as though the option were absent. Coinkite, Coldcard’s manufacturer, estimated effective entropy at roughly 40 bits for the Mk3 and about 72 bits for the Mk4, Mk5 and Q, compared with 128 bits for a standard 12-word BIP-39 seed. Block cautioned that these figures do not directly represent practical cracking costs and said it had not published a brute-force benchmark.
Affected devices and response
Coinkite released emergency firmware on July 31 for affected models. The update prevents new seeds from being created through the flawed process, but it cannot repair an already generated seed. Customers whose seeds may be exposed should create a replacement seed on patched firmware and transfer their funds. Restoring an old seed to an updated device or another wallet does not remove the risk.
- Mk3 firmware 4.0.1–4.1.9 is listed by Coinkite as affected, with a fix in 4.2.0; Block also includes earlier 4.0.0 builds and the Mk2 in the vulnerable path.
- Mk4 and Mk5 versions before 5.6.0, and Q versions before 1.5.0Q, are affected.
- Edge builds before 6.6.0X for Mk4/Mk5 and 6.6.0QX for Q are also included.
Coinkite said seeds created with at least 50 private, independent and fairly generated dice rolls are not vulnerable to this flaw alone, although it recommends migration when the process is uncertain. The company said TAPSIGNER, OPENDIME and SATSCARD use separate codebases and are unaffected. Galaxy noted that the sweep’s transaction pattern identifies a common operator, but does not by itself prove that the operator conducted the theft.
