EN ▼
Favorites
My Favorites
View All
Market Cap Price 24h%

Disclaimer: Content does not constitute investment advice. Trading involves risks—please invest with caution!

Coldcard's largest security breach could cause $70 million in damage

2026-08-01 12:12:31
Bookmark

Attackers steal more than 1000 bitcoins from nearly 1200 Coldcard wallets

On Friday, Galaxy Research revealed that an attacker stole more than 1000 bitcoins (approximately US$70 million) from nearly 1200 wallets that used Coldcard hardware to generate key seeds. This figure is much higher than the company's preliminary estimate 24 hours ago. Potential losses involve all Coldcard users who created seeds between March 2021 and the current date.

Galaxy Research estimates that a total of 1,082.65 bitcoins were withdrawn from 1196 addresses, with most of the funds transferred within 40 minutes between 01:10 and 01:50 UTC on July 30. This figure far exceeds the previously reported incident of 594 BTC ($38 million) stolen from about 500 single-signature wallets. Each affected address holds more than 0.15 BTC. More than 562 BTC was transferred to a specific address where no transactions had yet occurred.

The report highlights the work of Block's engineering and security teams in identifying these patterns of fund transfers. "The traces of on-chain transactions discovered by other researchers, including Clay Garrett, correctly point to the thieves. However, this did not identify the vulnerability that led to the theft,"the company noted, warning that" future attacks could target any Coldcard address generated using vulnerable firmware."

What's wrong with Coldcard's random number generator?

Coldcard is a hardware wallet that uses air gaps to isolate computers to store users 'bitcoins. The device uses a cryptographic signature method that is theoretically resistant to interception by any third party. It requires selecting a 24-word mnemonic phrase from a large number of potential words to generate seeds. In fact, however, the true entropy of Coldcard wallet was lower than expected.

Block's Bitcoin engineering and security team released a report detailing the issue. In Coldcard firmware, there are two instances that use random number generation functions with the same cryptographic signature, including a hardware implementation written by Coinkite and a software version ported from MicroPython. A build-time check to confirm the existence of environment settings failed to activate, causing some devices to use a defective software random number generator. The vulnerability has been fixed in the latest version 4.21, and the affected version dates back to the original version 4.0.0 released in March 2021. The flawed randomness is based on the processor's serial number and clock, which is considered unsafe.

Which users are affected by this vulnerability?

The first notification of this security issue came from Coinkite, which released a support page for Mk3 hardware users using firmware version 4.0.1 or higher. The company subsequently updated the announcement to include some Mk4, Mk5 and Coldcard Q devices and issued emergency firmware updates for all affected hardware.

Coinkite reportedly updated its official announcement, admitting that all existing devices could be affected by the attack, and that firmware upgrades would only provide partial security. According to Coinkite's announcement, in theory, all mnemonic phrase wallets generated before the release of version 4.21 are risky.

This vulnerability not only affects seed generation. Coldcard's paper wallet encryption, key splitting tool, mask generation, and Key Teleport function all use the same random number function.

Coinkite blames the theft on AI

Coinkite CEO Rodolfo Novak (NVK) issued an apology for the security issue, admitting that the company was responsible for errors in the mnemonic generation process. "We take full responsibility for the firmware vulnerability that caused this situation," he said, noting that a preliminary review of the vulnerability failed to reveal the issue. Novak speculated that attackers may have used AI to identify vulnerabilities, claiming that "this is a sobering reminder that we are entering a new paradigm that accompanies AI."

It is worth noting that Coinkite seems to contradict itself because of reports that the company used an AI system to scan its own code for potential security issues. The tool was reportedly used a few months ago, and Coinkite claimed that "it did not find this vulnerability or any other important issues." Both attackers and defenders can use the same tools, but in this incident, these tools seem to fail.

What should I do if I am a Coldcard wallet user?

Coinkite recommends that users update device firmware and create new mnemonic phrases, and recommends that users conduct test transactions to new wallet addresses before transferring large amounts of money. Users should keep old seeds as a backup because the document is needed after a transaction to regain access to funds.

After the news was disclosed, the price of Bitcoin (BTC) hardly changed. On Friday, BTC prices hovered around $63000.

Disclaimer:

All content published on this website, including hyperlinks, related applications, forums, blogs, and other media accounts, originates from third-party platforms and their users. CoinMarketInsight makes no representations or warranties of any kind regarding the website or its content. All blockchain-related data and materials are provided for informational and research purposes only and do not constitute financial, legal, or investment advice. Users and third parties are solely responsible for the content they publish. CoinMarketInsight shall not be liable for any losses arising from the use of this website. You should exercise caution and conduct your own independent research, review, analysis, and verification before making any decisions.

Read Full Article
More News
TOP

TOP