Loading market data...

Coinkite Halts Shipments, Destroys Inventory After $114M Coldcard Hack

Coinkite Halts Shipments, Destroys Inventory After $114M Coldcard Hack

Coinkite has halted all shipments and destroyed its remaining inventory after a series of hacks targeting Coldcard wallets resulted in over $114 million in stolen funds. The company confirmed that a vulnerability in the Coldcard Mk3 firmware, dating back to March 2022, allowed attackers to generate weak seeds and drain wallets.

The fourth wave

A fourth wave of attacks likely started Sunday evening, with 388.9 Bitcoins — over $29 million — moved in new transactions. The biggest single transaction so far was 51 Bitcoins, according to Trezor's Josef Tětek. The theft began Thursday, when hackers took over $35 million in Bitcoin from wallets.

How the hack worked

The vulnerability is a firmware bug in Coldcard Mk3 devices starting with version 4.0.1, released in March 2021. Instead of using the hardware true random number generator (TRNG), the seed generation fell back to a weak software pseudorandom number generator (PRNG). That made the seeds predictable. Coinkite admitted all of its models were vulnerable after further thefts.

Coinkite's response

Coinkite urged customers to move funds immediately. The company destroyed its remaining Coldcard inventory and halted all shipments. In a statement, Coinkite said the last three days have been some of the hardest in the company's history, acknowledging broken trust and permanent damage for some users.

Block's investigation

Engineers at Block investigated the hack and reported that the hackers used a top blockchain services provider to move funds. Block contacted that provider and federal authorities. The company has not named the provider or specified which agencies are involved.

Coinkite has not yet announced a timeline for resuming shipments or releasing a patched firmware. For now, the company's only advice is to move funds off any Coldcard device immediately.