Showing posts with label coldcard exploit. Show all posts
Showing posts with label coldcard exploit. Show all posts

$70 Million in Bitcoin Vanished From Coldcard Wallets - Make Sure YOUR Crypto is Safe...

For years the whole pitch behind a Coldcard was that nobody could reach your Bitcoin unless they were physically holding the device in their hands.

That promise came apart this week, when an attacker quietly swept around 1,082 BTC, worth roughly $70 million, out of more than a thousand wallets in under an hour. The unsettling part is that the thief never touched a single device, never phished anyone, and never needed a PIN or a password. These coins were sitting in cold storage, offline, kept exactly the way every self-custody guide tells you to keep them. And they walked out anyway. For a corner of crypto that treats hardware wallets as the gold standard of safety, this is a genuinely rough moment.

Blockchain analysts at Galaxy Digital, who have been tracking the drain, first put the losses near $38 million before revising the number upward as more addresses turned up in the sweep. Hardware wallet maker Coinkite has confirmed the flaw and rushed out patched firmware, but by then the money was long gone. According to Coinkite's own security advisory, the theft happened roughly a day before the company managed to warn users publicly, so plenty of people watched their balances drop to zero before they had any idea anything was wrong. When your entire brand is built on paranoid, belt-and-suspenders security, a delay like that is about as bad as it gets. The company says it is still working to pin down the full scope of the damage.

A five-year-old bug in how the wallet made its keys

The root cause here is boring and alarming at the same time. When you set up a hardware wallet, it is supposed to build your seed phrase from true randomness, the kind that makes guessing it mathematically hopeless. Somewhere in a firmware build shipped back in March 2021, Coldcard's software started skipping its dedicated hardware random number generator and quietly fell back to predictable values pulled from the chip itself. Instead of the expected 128 bits of entropy, affected Mk3 devices were producing seeds with only about 40 bits, and later Mk4, Mk5 and Q models landed somewhere around 72 bits. In plain English, the recovery phrase that was meant to be unguessable became something a determined attacker with modern hardware could grind through.

What makes it worse is that this sat undetected for more than five years. Every wallet created on the affected builds carried the same weakness baked in from the very start, whether or not the owner ever did a single thing wrong. Some researchers have suggested that automated or AI-assisted tooling may have helped the attacker chew through the reduced keyspace fast enough to clear so many wallets in one sitting, though that claim has not been confirmed. Coinkite says the fixed firmware restores proper randomness, but a patch cannot rewrite history. Any seed generated on the old software still exists in its weakened form, which is exactly why the advice coming out now has been so blunt.

The people who got hit did everything "right"

This one stings because it landed on the folks who followed the standard advice to the letter. The drained wallets largely belonged to long-term holders who pulled their coins off exchanges years ago and left them sitting untouched in cold storage, which is supposed to be the responsible move. Their reward for being careful was watching those balances vanish while newer and less disciplined traders on custodial platforms were completely unaffected. There is a bitter twist buried in here too. Users who bothered to add their own dice rolls during setup, or who layered on a passphrase or a multisig arrangement, appear to have been protected, because that extra input put back the randomness the firmware had thrown away, and the people most exposed were the ones who simply trusted the device to handle its single most important job.

What to do if you own one

If you have a Coldcard, the guidance from Coinkite is direct: treat your seed as compromised and move your funds. That means updating to the patched firmware, generating a brand new seed on that updated hardware, and then sending everything over to the fresh wallet, because a firmware update on its own fixes nothing when the weak seed already exists. Annoyingly, there is no self-test that tells you whether your particular seed falls inside the guessable range, so the only safe assumption is that it might. You can check your firmware version under the Advanced menu on the device, and anything generated on the vulnerable builds between 2021 and the recent fix should be treated as suspect. Bitcoin slipped about 3% as the scale of the mess sank in, and the timing hands an easy talking point to everyone who has been pushing regulated custodians and spot ETFs over do-it-yourself storage.

The uncomfortable lesson is that "not your keys, not your coins" was always sold as the safer road, and for the most part it still is, but your keys only protect you if they were actually random to begin with. A single quiet build error hid for half a decade inside one of the most trusted names in Bitcoin self-custody, and it took a $70 million heist for anyone to catch it. None of this means hardware wallets are a scam or that cold storage is suddenly dead. It does mean the unglamorous stuff, the firmware updates and the extra entropy and the passphrases and the multisig setups, is the part that quietly saves you, right up until the day it turns out to be the only thing standing between you and an empty wallet.

---------------

Author: Cedric Holloway
New York Newsroom
Breaking Crypto News