
Hackers have stolen an estimated $130 million in Bitcoin from users of Coldcard hardware wallets after exploiting a flaw that made some recovery phrases easier to predict. Blockchain researchers believe at least 12 separate attackers are targeting affected wallets, although their identities remain unknown.
Coldcard devices are designed to keep the seed phrase controlling a Bitcoin wallet offline. The attack did not require hackers to access the physical devices because the flaw reduced the randomness used to generate some seed phrases.
Seed Generation Used Weaker Randomness
Coldcard maker Coinkite said a series of software integration errors prevented its intended hardware random-number generator from contributing enough randomness during seed creation. A software fallback generated seeds with a smaller search space, making them more practical for attackers to guess through automated testing.
The most severely affected Coldcard Mk2 and Mk3 firmware produced an estimated 40 bits of effective entropy rather than the intended 128 bits. Later Mk4, Mk5 and Q models received additional randomness from secure components but still produced only about 72 bits under affected firmware, according to Coinkite’s technical explanation.
Once attackers understood how the phrases were generated, they could search through possible combinations until they found one controlling a funded wallet. They could then transfer the Bitcoin without stealing the device or obtaining the owner’s written backup.
Security researchers at Block published further analysis of the predictable random-number generation. Coinkite said it must assume someone found the flaw by examining older versions of its publicly available firmware.
Offline Storage Did Not Protect Affected Wallets
One reported victim, Jonathan Goodman, said approximately $1.6 million was removed from his Coldcard wallet despite keeping his devices offline and storing his backups in secure locations. The failure occurred when the seed phrase was first created, meaning later physical protections could not restore the missing randomness.
Cold wallets are generally considered safer than internet-connected wallets because their private keys do not need to reach an online device. However, their security still depends on generating an unpredictable key at the beginning.
Galaxy Research estimated that attackers had taken around $130 million by Tuesday. Elliptic co-founder Tom Robinson told TechCrunch that the figure was broadly consistent with his company’s monitoring.
Coinkite Tells Users to Replace Affected Seeds
Coinkite has released corrected firmware for every affected Coldcard model. Its security advisory warns that installing the update does not repair a seed created with vulnerable software.
Affected users should install the corrected firmware, generate a completely new seed phrase and transfer their funds to the new wallet. Coinkite recommends testing the replacement wallet with a small transaction before moving the remaining balance.
Seeds created with at least 50 independent and private dice rolls are not considered exposed by this flaw alone. A strong, unique BIP-39 passphrase may also reduce the immediate danger, but Coinkite still advises those users to migrate because the underlying seed remains affected.
Featured image credits: Magnific.com
For more stories like it, click the +Follow button at the top of this page to follow us.
