Firmware flaw in Coldcard hardware wallets exposed private keys, enabling theft of over 2,055 BTC across multiple attacks.
A firmware vulnerability in Coldcard hardware wallets allowed attackers to generate private keys from a software-based random number generator instead of the device’s secure hardware chip. The flaw reduced entropy from 128 bits to roughly 40 bits on older models, making keys predictable and enabling the theft of over 2,055 BTC, valued at approximately $130 million at current prices.
The bug went unnoticed for eight years before Coinkite disclosed it on August 1. Galaxy Research tracked three confirmed waves of thefts, with a fourth suspected, including a $70 million sweep completed in 41 minutes. At least 15 separate attackers exploited the vulnerability, targeting wallets that had never been connected to the internet.
Coinkite attributed the issue to a 2021 migration to the libsecp256k1 cryptography library, which inadvertently rerouted seed generation to an insecure software source. The company released a technical backgrounder detailing the flaw and its impact on affected devices.