Coldcard Firmware Flaw Leads to $70 Million Bitcoin Theft
A critical vulnerability in seed generation allowed attackers to drain over 1,000 BTC from approximately 1,200 hardware wallet addresses.
A critical firmware vulnerability in Coldcard hardware wallets has resulted in the theft of more than 1,000 Bitcoin, valued at approximately $70 million. The exploit targeted roughly 1,200 addresses, sparking urgent warnings for users to migrate their assets immediately.
The breach centered on a failure in the wallets' secure randomness generator. Instead of producing truly random keys, the affected firmware utilized predictable software-based key generation. This flaw allowed attackers to reconstruct private keys offline, effectively bypassing the security of the hardware. The issue impacted Mk2 and Mk3 devices across firmware versions 4.0.0 through 5.0.3, though warnings were later expanded to include Mk4, Mk5, and Coldcard Q models.
The Cold Storage Paradox
Coldcard, produced by Canada-based Coinkite, is marketed as a high-security, Bitcoin-only solution that utilizes air-gapped transaction signing to isolate private keys from the internet. By design, these devices are intended to be the "gold standard" for long-term storage, removing the risk of remote hacking. However, this incident demonstrates a systemic risk: when the flaw exists at the point of seed generation, the physical isolation of the device becomes irrelevant. Because the keys were predictable, the security of the "cold" environment provided no protection against an attacker who could mathematically derive the seed.
Industry Implications
This attack undermines confidence in hardware wallets and the perceived safety of cold storage. The speed of the exploit—with hundreds of wallets drained in a matter of minutes—triggered immediate volatility in the Bitcoin market, as analysts monitored key support levels at $60,000 and $58,000. Beyond the immediate financial loss, the event highlights a growing concern within the cybersecurity community regarding the use of frontier Large Language Models (LLMs) by hacking teams to identify critical software vulnerabilities more rapidly than human auditors can patch them.
Recovery and Next Steps
Coinkite has issued emergency firmware updates to correct the generation process for new seeds. However, the company has clarified that updating the firmware does not secure a previously compromised seed. Because the vulnerability is baked into the original key generation, any funds held on an affected seed remain at risk regardless of the current firmware version. Users are instructed to generate entirely new seeds on updated devices and migrate their funds immediately. The industry continues to monitor for further exploits as the full scope of the predictable key generation flaw is analyzed.