Coldcard Wallet Bug Leads to $38 Million Bitcoin Theft in 25 Minutes

A firmware flaw in Coldcard hardware wallets enabled an attacker to steal 594 BTC, worth $38 million, from 500 wallets. An attacker exploited a vulnerability in Coldcard hardware wallets, draining 594 bitcoin, valued at $38 million, from approximately 500 single-signature

A firmware flaw in Coldcard hardware wallets enabled an attacker to steal 594 BTC, worth $38 million, from 500 wallets.

An attacker exploited a vulnerability in Coldcard hardware wallets, draining 594 bitcoin, valued at $38 million, from approximately 500 single-signature wallets within 25 minutes. The flaw, present in firmware versions since March 2021, bypassed hardware randomness generators, making private keys predictable.

The bug affected Coldcard Mk3 devices running firmware 4.0.1 or later, while newer models like Mk4, Q, and Mk5 remained unaffected. Most stolen funds originated from wallets holding over 0.15 BTC, many of which had been inactive for years. The attack consolidated 562 BTC into a single address, which has not moved since.

Coinkite, the wallet’s manufacturer, issued warnings to affected users but noted the theft had minimal impact on BTC’s market price. The incident highlights risks in hardware wallet security despite their reputation for safeguarding assets.

Leave a Reply

Your email address will not be published. Required fields are marked *