Particle.news
Download on the App Store

Coldcard Firmware Flaw Lets Hackers Drain Roughly 1,600–2,055 BTC

A 2021 firmware change weakened seed randomness, prompting users with affected wallets to generate new seeds then transfer their bitcoin immediately.

Overview

  • Coinkite disclosed that a March 2021 firmware build caused some Coldcard devices to fall back to a deterministic MicroPython generator instead of the STM32 hardware random-number generator, sharply reducing entropy used to create recovery seeds.
  • Researchers from Galaxy and others say attackers began coordinated sweeps after the bug was disclosed, with confirmed thefts of about 1,596 BTC from roughly 7,300 addresses and suspected losses rising toward 2,055 BTC as more waves were tracked.
  • Because the flaw lets attackers reconstruct private keys offline, victims lost funds without phishing or device theft, and Coinkite’s emergency firmware update (v4.2.0) only prevents new weak seeds rather than fixing already compromised wallets.
  • On‑chain monitoring shows at least 15 distinct attacker clusters and that about 90% of stolen coins remain in attacker-controlled addresses, with investigators and exchanges alerted and some funds routed toward mixing services in limited cases.
  • The incident has driven a mass migration of wallets, sharp inflows into exchanges and spot ETFs, and an AI-assisted community audit that flagged thousands of vulnerabilities, raising questions about firmware verification, self-custody risk, and next steps for large holders.