Particle.news
Download on the App Store

Coldcard Firmware Flaw Lets Attackers Steal an Estimated 1,600–2,100 BTC

The 2021 build routed seed creation to a predictable software random-number generator, making many recovery phrases enumerable and forcing affected owners to generate new seeds and move funds.

Overview

  • Coinkite says firmware versions 4.0.1 through 4.1.9 routed seed generation to a software pseudo-random generator that cut effective entropy from the expected 128 bits to roughly 40–72 bits.
  • Investigators traced coordinated sweep waves that began on July 30 and estimate between about 1,600 and 2,100 BTC were stolen after attackers reconstructed vulnerable seeds without touching the physical devices.
  • Coinkite released patched firmware that fixes future seed generation but cannot make existing compromised recovery phrases secure, so affected users must create new seeds on patched devices and transfer funds.
  • The exploit triggered a broad defensive migration of bitcoin, with on-chain data showing roughly 233,000 BTC moved out of long-term holder wallets and about 22,000 BTC sent to exchanges as users sought safer custody.
  • Forensics firms report most stolen coins remain consolidated with limited early laundering, investigators continue to trace attacker clusters, and the episode has renewed debate over self-custody, device audits, and multisignature protections.