Loading market data...

Over $70M in Bitcoin Stolen Through Coldcard Hardware Wallet Bug

Over $70M in Bitcoin Stolen Through Coldcard Hardware Wallet Bug

More than $70 million worth of Bitcoin has been drained from Coldcard hardware wallets through a firmware vulnerability that made private keys predictable. The attacker used a paid account at a well-known blockchain-services provider to sweep funds from single-signature addresses, and engineers warn that more addresses could still be at risk.

A firmware bug that went unnoticed for years

The vulnerability traces back to a bug in Coldcard Mk3 devices starting with firmware version 4.0.1, released in March 2021. Instead of using the hardware true random number generator, the bug caused seed generation to fall back to a weak software pseudorandom number generator. That made private keys for single-signature wallets — especially those created without dice rolls or a strong BIP-39 passphrase — predictable enough for an attacker to brute-force.

The attacker's methodical sweep

Clay Garrett, an engineer at Blockstream, spotted the unusual pattern in the sweeps and contacted the blockchain-services provider, who requested anonymity. Authorities were notified. Galaxy Digital's research arm later confirmed that the same attacker was behind all the thefts, noting a distinctive coin-moving pattern across the transactions.

Coinkite's shifting story

Coinkite initially said only Mk3 devices were vulnerable. But after additional thefts, the company admitted that all Coldcard models were affected. Engineers have since warned that more Bitcoin addresses could be at risk, though the full scope of the exposure remains unclear.

Next steps for Coldcard users

Bitcoiners are being advised to move funds out of single-signature Coldcard addresses and into secure custody. The company has not yet released a patch, and the attacker is still active. Authorities are investigating, but no arrests have been announced.