LATEST NEWS
SELECTED FOR YOU

Coldcard’s biggest security failure may have cost $70M

ByAshish KumarAshish Kumar
3 mins read
Coldcard's biggest security failure may have cost $70M
  • Over 1,082 BTC (~$70M) was stolen from 1,196 Coldcard wallets in a 40-minute attack, affecting seeds generated since March 2021.
  • The flaw was caused by weak randomness in Coldcard firmware 4.0.0–4.2.0, making wallet seeds potentially predictable.
  • Coinkite urges users to update firmware and move funds to a newly generated wallet after testing the new address.

An attacker has drained over 1,000 bitcoin (approx worth around $70 million) from nearly 1,200 wallets that used Coldcard hardware to generate a key seed, Galaxy Research revealed on Friday. The figure is substantially higher than the initial estimates made by the company 24 hours earlier. The potential losses involve all Coldcard users who created a seed between March 2021 and the present date.

Galaxy Research estimates that 1,082.65 bitcoin were withdrawn from 1,196 addresses, with the majority of the funds moved between 01:10 and 01:50 UTC on July 30, in a 40-minute window. This number vastly exceeds the reported theft of 594 BTC ($38 million) from approximately 500 single-signature wallets. It happened within 40 minutes. Each of the affected addresses owned more than 0.15 BTC. Over 562 BTC were transferred to one particular address that has yet to see any transactions.

The report highlighted the work of Block’s engineering and security teams, which recognized a pattern in the movement of these funds. “The trail of on-chain transactions identified by other researchers, including Clay Garrett, correctly points to the thief. However, it does not identify the vulnerability that enabled this particular theft,” the company noted, warning that “future attacks could target any Coldcard address generated using the vulnerable firmware.”

How Coldcard’s RNG went wrong?

Coldcard is a hardware wallet that utilizes an air-gapped computer to store the user’s bitcoin. The device employs a cryptographic signing method that should theoretically resist any third-party attempts at interception. It requires a 24-word mnemonic phrase for seed generation that is chosen from a large set of potential words. In reality, the true entropy of a Coldcard wallet was lower than expected.

Block’s Bitcoin Engineering and Security teams published a report that detailed the issue. Within the Coldcard firmware, there were two instances of a function that generated random numbers with the same cryptographic signature, including the hardware implementation written by Coinkite and a software version carried over from MicroPython. 

A build-time check that confirmed the presence of the environment setting failed to activate, resulting in some devices utilizing the compromised software random number generator. This vulnerability was patched in the most recent 4.21 release, with the affected versions tracing back to the initial 4.0.0 release from March 2021. The compromised randomness was based on the processor’s serial number and clock, which are not considered secure.

Who is affected by the vulnerability?

The first notice about the security problem came from Coinkite, which published a support page for users who utilized Mk3 hardware with firmware 4.0.1 or newer. The company updated the advisory to also include certain Mk4, Mk5, and Coldcard Q devices and released emergency firmware updates for all affected hardware.

According to reports, Coinkite updated its official advisory to acknowledge that all existing devices are potentially vulnerable to this attack, with firmware upgrades providing only partial security. In theory, all wallets with mnemonic phrases generated before the release of version 4.21 are at risk, according to the Coinkite advisory.

The vulnerability affects more than just seed generation. Coldcard’s paper wallet encryption, key splitting tools, mask generation, and Key Teleport feature all utilize the same randomness function.

Coinkite blames AI for the heist

Coinkite CEO Rodolfo Novak (NVK) published an apology for the security issue, acknowledging that the company was responsible for the error in the mnemonic generation process. “We took full accountability for the firmware bug that led to this situation,” he stated, noting that the initial review of the vulnerability had failed to catch the issue. Novak speculated that the attacker could have used AI to identify the vulnerability, claiming that “this is a sobering reminder of the new paradigm we are entering with AI.”

It is worth noting that Coinkite appears to be arguing against itself, since the Decrypt article notes that the company once used an AI system to scan its own code for potential security problems. That tool was reportedly utilized a few months earlier, with Coinkite claiming that “it did not find this vulnerability or anything else of significance.” Attackers and defenders all have access to the same tools, but in this case, it seems that they failed to do their job.

What should I do if I am a Coldcard wallet owner?

Coinkite recommends that users update the firmware on their devices and create new mnemonic phrases, advising users to make test transactions to the new wallet address before transferring any significant funds. Users should keep their old seed as a backup, as this document will be required to regain access to the funds after the transaction.

The price of bitcoin (BTC) has barely changed in the wake of this revelation. BTC price is hovering near $63,000 on Friday.

If you're reading this, you’re already ahead. Stay there with our newsletter.

FAQs

How much bitcoin was stolen in the Coldcard exploit?

Galaxy Research estimated 1,082.65 BTC, worth about $70 million, drained from 1,196 addresses on July 30, up from an earlier CoinDesk figure of roughly 594 BTC, or $38 million, from about 500 wallets.

What caused the Coldcard vulnerability?

A firmware build error introduced in version 4.0.0 in March 2021 caused devices to skip their hardware randomness generator and fall back to predictable software key generation seeded by nonsecret chip data such as the serial number and clock registers.

Which Coldcard models are affected?

Coinkite first flagged Mk3 devices on firmware 4.0.1 or later, then expanded the warning to certain Mk4, Mk5 and Coldcard Q builds. Reports claim that the firm now considers every current model affected to some degree.

Share this article

Disclaimer. The information provided is not trading advice. Cryptopolitan.com holds no liability for any investments made based on the information provided on this page. We strongly recommend independent research and/or consultation with a qualified professional before making any investment decisions.

Ashish Kumar

Ashish Kumar

Ashish Kumar is a crypto and financial journalist with eight years of newsroom experience. He covers what’s happening with crypto markets, regulation, DeFi, and exchange ecosystems. He has worked with Coingape, Todayq, and Newsroompost. Ashish holds a PGDP in English Journalism from the IIMC. He has also interviewed industry figures including Arthur Hayes, Yat Siu, Austin Federa, and more.

MORE … NEWS