$38M Drained in Bitcoin: Coldcard Hardware Wallet Exploit Traced to Critical Firmware Vulnerability
A critical firmware flaw in Coldcard hardware wallets bypassed the hardware RNG, leading to $38M in Bitcoin being drained from nearly 500 wallets. Learn what happened, which firmware versions are affected, and the crucial steps you need to take immediately to secure your funds.
Coldcard Security Alert: $38 Million Drained in Critical Firmware Vulnerability
The hardware wallet ecosystem experienced a major security breach today following a critical firmware flaw affecting Coldcard devices. The vulnerability has reportedly resulted in the draining of roughly 594 Bitcoin (worth approximately $38 million) across nearly 500 wallets.
For a product long considered a gold standard among Bitcoin maximalists and cold-storage advocates, the incident marks one of the most severe hardware wallet exploits in recent memory.
What Happened?
The exploit stems from a severe bug in the device's seed-generation process linked to firmware versions originating as far back as March 2021.
According to security findings:
- The Root Cause: A faulty code check caused affected Coldcard devices to bypass the built-in Hardware Random Number Generator (RNG).
- Weakened Key Strength: Instead of using the hardware RNG, devices fell back on a significantly weaker software source. On legacy Mk3 devices running firmware version 4.0.1 or later, key security dropped from an intended 128-bit strength down to roughly 40 bits.
- Affected Models: Beyond the Mk3, seeds generated on Mk4, Q, and Mk5 models prior to the patch were also degraded to roughly 72 bits of security, making them vulnerable to brute-force key extraction attacks.
Immediate Actions for Coldcard Users
If you use a Coldcard device or generated seeds on affected firmware versions, immediate precautions are strongly advised:
- Verify Your Firmware: Ensure your hardware device is updated to the latest, patched firmware version released by Coinkite/Coldcard.
- Re-evaluate Seed Entropy: If your wallet seed phrase was generated on a vulnerable firmware version, updating the firmware alone may not make previously generated keys safe. Moving funds to a freshly generated wallet created on secure firmware (or another verified setup) is critical.
- Monitor Official Communications: Follow official updates directly from the official Coldcard social accounts and security advisories for step-by-step mitigation guidance.
The Takeaway
This incident serves as a stark reminder that even air-gapped, dedicated hardware solutions rely heavily on software integrity. As the situation unfolds, users are encouraged to audit their setups, update their software, and ensure proper security practices across all self-custody solutions.
