Particle.news

Coldcard Firmware Bug Lets Attackers Drain Millions in Bitcoin

A 2021 build error made older Coldcard seeds guessable, forcing owners to replace seeds on patched devices to stop further thefts.

Overview

  • Blockchain analysts say attackers swept vulnerable single-signature Coldcard wallets on July 30–31, with loss estimates ranging from about 594 BTC (roughly $38 million) to 1,082.65 BTC (about $70 million) as different teams mapped the drains.
  • Independent reviews traced the flaw to a March 1, 2021 build change that caused the device to skip its hardware random number generator and fall back to a predictable MicroPython software routine.
  • Coinkite released emergency firmware fixes for Mk3/Mk4/Mk5/Q branches but warned that installing updates does not change seeds already created under the vulnerable builds.
  • Users with seeds generated on affected firmware are urged to update their device, generate an entirely new seed on patched hardware, verify with test transactions, and move funds because dormant single-signature wallets were the main targets.
  • The incident highlights that open source code and powerful tooling can speed both review and exploitation, increases calls for multisig and external entropy like BIP-39 passphrases or dice, and leaves investigations and on-chain tracking ongoing.