Back brokenews

Coldcard seed-generation flaw drains Bitcoin wallets

What every side agrees happened

A firmware flaw in Coldcard hardware wallets, present since March 2021, caused affected devices to generate low-entropy seed keys, leaving users exposed to theft. Coinkite, the wallet's maker, said in its security advisory that "Coinkite is warning all users who generated a seed using a Mk3 on version 4.0.1 (March 2021) thru 4.1.9 (inclusive) that their funds may be at risk."1

An attacker exploited the weakness to drain funds from roughly 500 single-signature wallets in a short window. CoinDesk reported that "an attacker exploited a flaw in how some Coldcard hardware wallets generated keys to steal roughly 594 bitcoin, worth about $38 million, from around 500 single-signature wallets in under 30 minutes."2

Other outlets put the scale of the theft higher. AMBCrypto reported that "Galaxy identified 1,196 addresses containing approximately 1,082.65 BTC, valued at around $70.2 million, that were drained over a 41-minute period."3 Bitcoin Magazine cited similar figures, noting that "since then, a total of 1,082.65 Bitcoins have disappeared from wallets, according to data from Galaxy Research and engineers at payments company Block."4

Decrypt reported an AI angle to how the flaw was found, stating that "Coinkite believes an attacker used AI to find a flaw that has cost owners of its Coldcard hardware wallets tens of millions of dollars in Bitcoin, and says its own AI review of the same code weeks earlier turned up nothing."5

The incident drew strong reaction within the Bitcoin community. CoinDesk quoted commentator Guy Swann as saying "this is the worst hit in bitcoin history to the most knowledgeable and 'properly secured' bitcoiners."2

Reports differ on the exact scale of the loss and on how the vulnerability was discovered.

Written by brokenews from 6 sources · Machine-drafted, verified against every source · Methodology →

Notes & sources

6 sources · 7 articles
Skip the source list ↓
← Back to today