Hardware Wallet Flaw Drains $90 Million in Bitcoin After Five-Year Undetected Bug

A seed-generation flaw in Coldcard devices led to 4,500 compromised addresses and nearly $90 million in Bitcoin losses. A five-year-old flaw in Coldcard hardware wallets has resulted in nearly $90 million in Bitcoin being drained from over 4,500 addresses. The bug, introdu

A seed-generation flaw in Coldcard devices led to 4,500 compromised addresses and nearly $90 million in Bitcoin losses.

A five-year-old flaw in Coldcard hardware wallets has resulted in nearly $90 million in Bitcoin being drained from over 4,500 addresses. The bug, introduced in March 2021, routed seed generation to a weaker random number generator instead of the intended cryptographic library, evading detection during audits.

The vulnerability highlights a gap in independent testing of hardware wallets, as auditors verified the presence of a secure generator but not its actual use in production firmware. Kraken’s chief security officer called the incident a “wake-up call” for manufacturers to ensure rigorous verification of critical functions.

Coldcard disclosed the flaw last week, revealing the migration to a new cryptographic library inadvertently triggered the issue. The ongoing attack exploits weak seed phrases generated by affected devices, raising concerns about consumer trust in hardware wallet security.

Leave a Reply

Your email address will not be published. Required fields are marked *