Particle.news
Download on the App Store

Coldcard Firmware Bug Lets Attackers Reconstruct Seeds and Drives Over $100 Million in Bitcoin Thefts

Coinkite issued emergency fixes after a 2021 randomness error made some Coldcard recovery seeds predictable.

Overview

  • Blockchain analysts traced rapid coordinated sweeps that began on July 30 and emptied thousands of single-signature Coldcard addresses without touching victims’ devices.
  • A March 2021 firmware change caused the wallet to fall back to a software pseudo-random number generator during seed creation, collapsing expected entropy and making seeds enumerable.
  • Coinkite released emergency firmware, destroyed vulnerable inventory, and told customers that any seed generated on affected builds is irreparably weak and must be replaced and migrated.
  • Galaxy Research has confirmed 1,596 BTC stolen across thousands of addresses and warned totals could rise to about 2,055 BTC if a suspected fourth wave is validated, while investigators have shared clustered attacker wallets with law enforcement and exchanges and say most stolen coins remain unmoved.
  • The exploit has pushed many users to move funds, distorted on-chain metrics for small transfers, and renewed debate over self-custody versus custodial or multi-signature custody options for protecting long-term holdings.