Coldcard firmware flaw compromised 1,367 BTC across thousands of hardware wallets
A firmware bug in Coldcard devices weakened seed generation, enabling attackers to reconstruct private keys and steal Bitcoin without phishing or malware.
Binance founder Changpeng Zhao highlighted a critical vulnerability in Coldcard hardware wallets, reigniting debate about the security of devices marketed as hack-proof. A firmware integration error introduced in March 2021 allowed the devices to fall back on deterministic methods for generating recovery seeds, rather than relying consistently on hardware random-number generators.
Galaxy Research traced losses to 1,367.05 BTC across 4,585 addresses, valued at roughly $88.6 million. The earlier analysis identified 1,082.65 BTC stolen from 1,196 addresses in a 41-minute sweep on July 30. Block's security teams determined that the fallback mechanism used chip identifiers and timing data, enabling attackers to narrow possible inputs and generate candidate seeds offline. Once an attacker matched a reconstructed seed to a funded address on the blockchain, they could derive the corresponding private keys and transfer funds.
Coinkite reported that Coldcard Mk2 and Mk3 devices running firmware versions 4.0.1 through 4.1.9 generated critically weak seeds. Mk4, Mk5, and Q devices created before emergency patches held approximately 72 bits of entropy instead of the intended 128 bits, making the seed space significantly easier to search. Firmware updates cannot retroactively strengthen old seeds already generated by vulnerable software; users must update devices, generate new seeds, and move funds to fresh addresses.
Zhao advocated for spreading holdings across multiple wallets with independently generated seeds to limit losses from a single compromised device. However, he acknowledged that this approach introduces its own risks—lost backups, poor recovery planning, and potential user error across multiple devices. The takeaway reflects a shift from seeking one perfectly secure wallet to mitigating damage when any single system fails.
These two are not the same thing, and one does not produce the other. The left is how this single article reads, from its tone alone. The right is the site’s own call on the asset, from indicators and analysis. Press tone feeds no score and no signal: on the only corpus this site has measured, daily tone tracked the move that had already happened and showed no measurable link with what followed.
More on Bitcoin All pieces →
- Neutral Block Files for US National Trust Bank Charter to Consolidate Crypto Custody
- Neutral Tokenized Asset Holders Cross 3.5 Million as Institutional Inflows Rebound
- Neutral Iran Eases Currency Restrictions to Permit Cross-Border Crypto Settlements
- Neutral Block Seeks OCC Approval for Builders Bank & Trust to Manage Digital Assets
Rewritten from the headline, the teaser and the one-line summary the qualification step produced — that is all the material there is, and nothing is added to it. The source link is kept on file so any item can be checked, and is not published here.