Loading market data...

Bitcoin Devs File 4,962 Security Findings After Coldcard Theft Spree

Bitcoin Devs File 4,962 Security Findings After Coldcard Theft Spree

Volunteer developers filed 4,962 security findings across 390 Bitcoin projects in about 30 hours, after the Coldcard vulnerability that allowed predictable seed generation and confirmed thefts of 1,596 BTC — over $100 million. The audit, triggered by that incident, found 85 critical and 635 high-severity issues. Only one of the 391 codebases reviewed came back clean.

The Coldcard trigger

The Coldcard bug let an attacker guess a wallet's seed with just 32 bits of entropy. Confirmed thefts reached 1,596 BTC, and the suspected total is closer to $130 million. The timing isn't great for hardware wallet makers — that category had the second-lowest rate of serious flaws at 9.6%, but the damage was already done.

Korean holders largely escaped because dice-based seeds are common there. That's a small comfort for everyone else.

Where the flaws piled up

Privacy tools had the highest rate of serious issues at 24%, while crypto libraries produced the most findings overall — 1,385 across 128 projects. One hour absorbed 4,101 findings as a backfill, not live scanning. Excluding that, the pace was roughly 29 findings per hour. Not exactly a calm afternoon.

Of all findings, 91% came from automated scanning, and only eight were false positives. About 21.4% included proof-of-concept code. That's a lot of reproducible bugs.

The gap between finding and fixing

Only 147 findings have reached maintainers, and 246 carry no severity label. That's a bottleneck. Rob Hamilton spent over $10,000 scanning 100+ libraries and found multiple serious vulnerabilities on his own — the kind of work that doesn't scale without funding.

OpenSats launched a Code RED grant track to pay researchers who disclose flaws and refund AI-related expenses. It's a start, but the backlog is real.

Market shrugs it off

The Bitcoin market didn't flinch. BTC traded near $64,396, up 0.5% over 24 hours. Active addresses spiked to a 20-month high following the Coldcard incident, though that's more about attention than panic.

This isn't the first weak-randomness bug — the 2023 Milk Sad bug and May's Ill Bloom vulnerability, which drained $5.7 million, both fit the pattern. The difference is scale.

Next up: whether maintainers can triage 4,962 findings before the next exploit. The clock's already ticking.