EN ▼
Favorites
My Favorites
View All
Market Cap Price 24h%

Disclaimer: Content does not constitute investment advice. Trading involves risks—please invest with caution!

Using Coldcard vulnerability to steal more than $70 million in Bitcoin, the thief is connected to a

2026-08-01 12:15:40
Bookmark

Major security breach shakes Bitcoin community: More than US$70 million was stolen due to Coldcard vulnerability

A major security breach shocked the Bitcoin community. Attackers used a vulnerability in Coldcard's hardware wallet to steal more than US$70 million worth of Bitcoin. Investigation revealed that the attacker used a leading blockchain service provider in the industry to carry out the theft.

Abnormal transaction patterns alert investigators

Clay Garrett, an engineer at payment technology company Block, said that after discovering suspicious bitcoin transfers, the team immediately contacted a well-known blockchain service provider. Garrett reported that an analysis of trading activity found that attackers showed a unique pattern when collecting funds.

Garrett explained that this pattern points to the conclusion that the thief had a paying account with the well-known blockchain service provider. This allows him to systematically query the source address and perform related actions during the theft. At present, relevant departments have been notified and the investigation is still in progress.

Garrett described how the transaction sequence reveals: "The operator uses a paying account with a well-known blockchain service provider to query the source address and perform other related activities during the collection of funds." He pointed out that this had been confirmed and law enforcement had been informed.

At the request of relevant representatives, the name of the blockchain service company has not yet been disclosed. However, these trading models have raised questions about the role such platforms may play in promoting large-scale illegal transfers of digital assets.

Galaxy Digital, a diversified financial services and investment management company focusing on digital assets, also highlighted these trading models. Its research department commented that although the attacker's method of transferring currency is unique, it is not unique enough to reveal the method used by the hacker attack itself.

According to Galaxy Digital researchers: "This model tells us that these operations were all done by the same attacker-it did not capture the attack itself and behaved like a coin owner transferring currency on his own." They advise Bitcoin users to transfer funds from single-signed Coldcard addresses to a more secure escrow solution.

Coldcard vulnerability: firmware flaw exposes wallet

Coinkite, manufacturer of Coldcard hardware wallets, reported that a firmware vulnerability in Coldcard Mk3 devices led to the intrusion. The flaw, introduced with version 4.0.1 in March 2021, causes devices to rely on weaker software-based pseudo-random number generators for seed creation rather than hardware-based true random number generators. This allows attackers to predict wallet seeds and brute-force private keys, especially for accounts that do not use dice entropy or strong BIP-39 passphrases, which is extremely risky.

Micro Dictionary: Pseudorandom Number Generator

A software algorithm for generating sequences of numbers that appear random but are determined by initial values. It is less secure than a true random number generator that uses unpredictable physical processes.

Initially, Coinkite said the vulnerability was limited to specific models and firmware versions. However, after discovering more thefts, the company later admitted that all Coldcard models present similar risks. The company has advised users to update firmware and move assets from affected wallets.

Device/version vulnerability risk
High PRNG vulnerability in seed generation in Coldcard Mk3 (v4.0.1+)
Similar vulnerabilities in other Coldcard models

Warning has been issued that more Bitcoin wallets may still be at risk, and engineers are assessing the scope of the breach. As of now, at least $70 million worth of Bitcoin has been transferred from stolen wallets.

What is Coinkite?

Coinkite is a Canadian company focusing on Bitcoin security solutions, including cold-storage hardware wallets such as Coldcard. Its products are widely used in the cryptocurrency field for secure offline storage of digital assets.

Disclaimer:

All content published on this website, including hyperlinks, related applications, forums, blogs, and other media accounts, originates from third-party platforms and their users. CoinMarketInsight makes no representations or warranties of any kind regarding the website or its content. All blockchain-related data and materials are provided for informational and research purposes only and do not constitute financial, legal, or investment advice. Users and third parties are solely responsible for the content they publish. CoinMarketInsight shall not be liable for any losses arising from the use of this website. You should exercise caution and conduct your own independent research, review, analysis, and verification before making any decisions.

Read Full Article
More News
TOP

TOP