Coldcard Vulnerability Affects 4,500 Addresses, $90M Bitcoin Stolen
A five-year seed generation flaw in Coldcard hardware wallets has led to the theft of nearly $90M in Bitcoin across over 4,500 addresses, exposing critical gaps in firmware auditing.
Woofun AI reports that a seed generation vulnerability in Coldcard hardware wallets has impacted over 4,500 addresses, resulting in the theft of nearly $90 million in Bitcoin. Kraken Chief Security Officer Nick Percoco highlighted that auditors verified the presence of expected random number generators but failed to confirm that production firmware actually invoked them. Coinkite disclosed the software flaw originated in March 2021, when integration of a new cryptographic library mistakenly redirected the wallet creation process to a weaker MicroPython generator.
Percoco noted that hardware wallets lack end-to-end verification processes comparable to NIST SP 800-90B and BSI AIS-31, meaning existing certifications have not systematically enforced checks for validated entropy sources in production firmware. Coldcard has suspended all device shipments since confirming the issue on Thursday and destroyed remaining affected units at its facility. Coinkite advised users not to discard their devices and stated its legal team will coordinate with law enforcement across multiple jurisdictions.
Comments
No comments yet.