Loading market data...

Coldcard Firmware Bug Drained $38M in Bitcoin, Users Urged to Move Funds

Coldcard Firmware Bug Drained $38M in Bitcoin, Users Urged to Move Funds

How the bug works

The flaw disables secure random number generation on certain Coldcard models. Attackers don't need physical access to the device. If they can see a wallet address or an exported public key, they can test guesses against the predictable private key — derived from the serial number and clock — and steal the funds. The exploit is similar to the Ill Bloom attack that drained wallets via weak seed phrases earlier this year.

Translation:

Jak chyba funguje

Chyba deaktivuje bezpečné generování náhodných čísel na některých modelech Coldcard. Útočníci nepotřebují fyzický přístup k zařízení. Pokud vidí adresu peněženky nebo exportovaný veřejný klíč, mohou testovat odhady proti předvídatelnému soukromému klíči — odvozenému ze sériového čísla a hodin — a ukrást prostředky. Zneužití je podobné útoku Ill Bloom, který letos dříve vyprázdnil peněženky prostřednictvím slabých seed frází.

Note: "Ill Bloom" is a proper noun, keep as is. "seed frází" - seed phrases. Third paragraph: Original:

Who is affected

Only the Coldcard Mk3 is vulnerable, and only if it's running firmware version 4.0.1 or later. The Mk4, Q, and Mk5 models are not affected. Coinkite and Block are still assessing the full extent of the flaw across older firmware versions. The vulnerability also extends to paper wallets and seed backups that relied on the same broken random number generator.

Translation:

Koho se to týká

Zranitelný je pouze Coldcard Mk3, a to pouze v případě, že běží na verzi firmwaru 4.0.1 nebo novější. Modely Mk4, Q a Mk5 nejsou postiženy. Coinkite a Block stále posuzují plný rozsah chyby napříč staršími verzemi firmwaru. Zranitelnost se také vztahuje na papírové peněženky a zálohy seedů, které spoléhaly na stejný rozbitý generátor náhodných čísel.

Fourth paragraph: Original:

What users should do

Coinkite recommends generating a new seed on a device with the latest firmware and transferring all funds to the new wallet. A firmware update alone won't undo the damage — the old seed is already compromised. Users who added an extra passphrase to their seed face substantially lower risk, but Coinkite still advises moving funds as a precaution.

Translation:

Co by měli uživatelé udělat

Coinkite doporučuje vygenerovat nový seed na zařízení s nejnovějším firmwarem a převést všechny prostředky do nové peněženky. Samotná aktualizace firmwaru škodu nevrátí — starý seed je již kompromitován. Uživatelé, kteří přidali k seedu extra přístupovou frázi, čelí výrazně nižšímu riziku, ale Coinkite přesto doporučuje přesunout prostředky jako preventivní opatření.

Fifth paragraph: Original:

The company is still working to determine how many devices and wallets were affected by the bug, which went undetected for years. For now, anyone with a Coldcard Mk3 that was updated after 2021 should treat their seed as exposed. The clock is ticking — and the attackers are still guessing.

Translation:

Společnost stále pracuje na určení, kolik zařízení a peněženek bylo chybou postiženo, která zůstala roky nezjištěna. Prozatím by každý, kdo má Coldcard Mk3 aktualizovaný po roce 2021, měl považovat svůj seed za ohrožený. Hodiny tikají — a útočníci stále hádají.

Now meta description: Original: "A firmware bug in Coldcard hardware wallets allowed attackers to predict private keys and steal 594.48 BTC. Coinkite urges users to move funds immediately." Translation: "Chyba firmwaru v hard