Back to top
  • 공유 Share
  • 인쇄 Print
  • 글자크기 Font size
URL copied.

Coldcard Wallet Flaw Exposes $100M Bitcoin Security Failure

Coldcard Wallet Flaw Exposes $100M Bitcoin Security Failure. Source: EconoTimes

A major Coldcard hardware wallet vulnerability has shaken confidence in Bitcoin self-custody after attackers reportedly stole more than $100 million in BTC from thousands of addresses.

Toronto entrepreneur Jonathan Goodman was among the victims. Despite keeping his Coldcard hardware wallet offline in a safe deposit box and storing his seed phrase separately, Goodman said attackers drained 18.25 Bitcoin, worth more than $1.17 million at the time. Galaxy Research estimated that roughly 1,596 BTC was stolen from around 7,300 addresses, with multiple attackers exploiting the weakness without needing physical access to the devices.

The security breach did not result from hackers directly accessing Coldcard devices. Instead, the problem originated in the process used to generate wallet seed phrases, which are essential for securing users' cryptocurrency.

The vulnerability reportedly entered Coldcard firmware during a major software overhaul in 2021. Coldcard was designed to obtain randomness from a dedicated hardware generator when creating new Bitcoin wallets. However, a configuration error caused the firmware to rely on a weaker software-based random number generator using information such as device and timing data.

Because this data was more predictable, attackers could dramatically reduce the number of potential seed phrases they needed to test. Coinkite estimated that some newer Coldcard devices generated seeds with only 72 bits of randomness instead of the intended 128 bits, creating far fewer possible combinations.

The vulnerable code was publicly available, but reviewers failed to trace the complete seed-generation process and identify which random number generator was actually being used. AI-assisted security reviews conducted before the theft also reportedly missed the flaw.

Coinkite has since released corrected firmware for affected Coldcard models. However, updating the firmware cannot repair vulnerable seed phrases that were previously generated. Users with affected wallets must install the latest firmware, create a new seed phrase and transfer their Bitcoin to new addresses.

The Coldcard hack highlights a critical Bitcoin self-custody risk: eliminating banks and exchanges does not eliminate trust entirely. Hardware wallet users still depend on manufacturers to generate their private keys securely.

<Copyright ⓒ TokenPost, unauthorized reproduction and redistribution prohibited>

Most Popular

Comment 0

Comment tips

Great article. Requesting a follow-up. Excellent analysis.

0/1000

Comment tips

Great article. Requesting a follow-up. Excellent analysis.
1