A seed-generation flaw in Coldcard devices led to 4,500 compromised addresses and nearly $90 million in Bitcoin losses.
A five-year-old flaw in Coldcard hardware wallets has resulted in nearly $90 million in Bitcoin being drained from over 4,500 addresses. The bug, introduced in March 2021, routed seed generation to a weaker random number generator instead of the intended cryptographic library, evading detection during audits.
The vulnerability highlights a gap in independent testing of hardware wallets, as auditors verified the presence of a secure generator but not its actual use in production firmware. Kraken’s chief security officer called the incident a “wake-up call” for manufacturers to ensure rigorous verification of critical functions.
Coldcard disclosed the flaw last week, revealing the migration to a new cryptographic library inadvertently triggered the issue. The ongoing attack exploits weak seed phrases generated by affected devices, raising concerns about consumer trust in hardware wallet security.