Coldcard firmware flaw exposes even offline hardware wallets to key compromise
A critical flaw in Coldcard's seed generation allowed attackers to silently compromise wallet keys for years, resulting in approximately 594 BTC stolen from around 500 addresses.
Hardware wallets sitting offline have long been considered among the safest custody methods available. That assumption now carries a significant caveat after Coinkite disclosed a critical entropy-generation vulnerability in Coldcard firmware.
The flaw reduced the randomness behind seeds generated on certain devices. Coinkite's advisory was direct: users must update to patched firmware, generate an entirely new seed, and migrate funds from anything created with the compromised version. A firmware patch corrects future key generation but cannot repair seeds already corrupted by weak randomness.
Security researcher 0xQuit detailed the mechanics, explaining how poor randomness in Coldcard's seed process enabled roughly 594 BTC to be swept from approximately 500 addresses in a short window. Critically, the device's PIN protection, air-gapped design, and secure element proved ineffective once the seed itself was compromised. 0xQuit recommended that holders of significant value move to multi-device multisig setups using at least two different vendors, writing seeds only on paper and splitting them geographically using Shamir secret sharing.
Block's technical investigation revealed the root cause: Mk2 and Mk3 firmware was supposed to use a hardware random number generator, but a firmware macro error forced the device to rely instead on a known device ID, timer state, and call history, making wallet generation deterministic rather than random. Newer models attempted compensation at boot, but a reseed process truncated that additional input to just 32 bits, still far below security standards.
These two are not the same thing, and one does not produce the other. The left is how this single article reads, from its tone alone. The right is the site’s own call on the asset, from indicators and analysis. Press tone feeds no score and no signal: on the only corpus this site has measured, daily tone tracked the move that had already happened and showed no measurable link with what followed.
More on Bitcoin All pieces →
- Neutral Block Files for US National Trust Bank Charter to Consolidate Crypto Custody
- Neutral Tokenized Asset Holders Cross 3.5 Million as Institutional Inflows Rebound
- Neutral Iran Eases Currency Restrictions to Permit Cross-Border Crypto Settlements
- Neutral Block Seeks OCC Approval for Builders Bank & Trust to Manage Digital Assets
Rewritten from the headline, the teaser and the one-line summary the qualification step produced — that is all the material there is, and nothing is added to it. The source link is kept on file so any item can be checked, and is not published here.