A firmware vulnerability in Coldcard hardware wallets enabled an attacker to drain over 1,082 Bitcoin (worth $70.2 million) from 1,196 addresses in just 41 minutes on July 30. Galaxy Research traced the theft to a March 2021 integration error in Coldcard's firmware that routed seed generation through a deterministic software pseudorandom number generator (PRNG) instead of using cryptographically secure randomness.
Coldcard, manufactured by Canadian firm Coinkite, markets itself as a Bitcoin-only hardware wallet designed for enhanced security. The flaw undermined this core premise by making private key generation predictable. An attacker who understood the vulnerable firmware version could mathematically derive the private keys protecting those wallets without physical access to the devices.
The vulnerability affected users running specific firmware versions that contained this flawed seed generation logic. Once an attacker identified wallets created with the vulnerable firmware, they could generate the same private keys offline and sweep funds to their own addresses. The 41-minute timeframe suggests the attacker either automated the process or had pre-calculated the vulnerable addresses beforehand.
This incident exposes a critical risk in hardware wallet deployments. Users often assume hardware wallets provide absolute protection because they keep private keys offline. Yet if the firmware generating those keys contains flaws, the offline storage provides no real benefit. The attacker never needed to compromise the physical devices.
Coinkite has not released a public statement about the vulnerability's discovery timeline or whether it issued a patch before the theft occurred. The firmware flaw appears to have persisted for years between March 2021 and July 2024, potentially affecting thousands of users who never updated their devices.
For Bitcoin holders, this incident reinforces several lessons. Hardware wallet users must apply firmware updates promptly, even if the devices seem secure. Wallets generated on
