Coldcard Hardware Wallet Flaw Linked to $70 Million Bitcoin Theft in 41 Minutes
Overview
On July 30, a significant security incident occurred involving Coldcard, a hardware wallet designed specifically for Bitcoin storage. An attacker exploited a flaw in the wallet's firmware, draining 1,196 Bitcoin addresses in a rapid 41-minute operation, resulting in a theft of 1,082.65 BTC, valued at around $70.2 million at the time. The issue stemmed from a 2021 firmware integration error that directed seed generation to a flawed pseudorandom number generator, compromising the wallet's security. This incident raises alarms for Coldcard users and highlights the risks associated with hardware wallets when firmware vulnerabilities are present. Users of Coldcard wallets should take immediate precautions to secure their assets and stay updated on any patches or fixes released by the manufacturer.
Key Takeaways
- Active Exploitation: This vulnerability is being actively exploited by attackers. Immediate action is recommended.
- Affected Systems: Coldcard hardware wallet by Coinkite
- Action Required: Users should update to the latest firmware version provided by Coinkite to address the vulnerability.
- Timeline: Newly disclosed
Original Article Summary
An attacker drained 1,196 Bitcoin addresses in 41 minutes on July 30, taking 1,082.65 BTC worth about $70.2 million at the time. Galaxy Research mapped the sweep and tied it to a firmware flaw in Coldcard, the Bitcoin-only hardware wallet made by Canadian firm Coinkite. A March 2021 firmware integration error routed seed generation to a deterministic software pseudorandom number generator (PRNG
Impact
Coldcard hardware wallet by Coinkite
Exploitation Status
This vulnerability is confirmed to be actively exploited by attackers in real-world attacks. Organizations should prioritize patching or implementing workarounds immediately.
Timeline
Newly disclosed
Remediation
Users should update to the latest firmware version provided by Coinkite to address the vulnerability.
Additional Information
This threat intelligence is aggregated from trusted cybersecurity sources. For the most up-to-date information, technical details, and official vendor guidance, please refer to the original article linked below.