Particle.news

Coldcard Firmware Flaw Lets Attackers Reconstruct Keys and Drain 1,367 BTC

Weakened seed entropy let attackers precompute private keys offline, leaving users to generate new seeds on patched devices to protect funds.

Overview

  • On July 30 an initial automated sweep emptied hundreds of dormant Coldcard addresses and by Aug. 2 on‑chain mapping from Galaxy Research showed roughly 1,367.05 BTC taken from about 4,585 addresses across multiple waves.
  • Block’s Bitcoin engineering team traced the root cause to a March 2021 firmware change that caused some builds to use a deterministic MicroPython fallback instead of the STM32 hardware random‑number generator, sharply reducing seed entropy.
  • Because the seeds had far less randomness, attackers could offline‑reconstruct private keys and sweep funds without touching victims’ devices, while multisig setups and seeds protected by strong independent entropy remained safe.
  • Coinkite released patched firmware on Aug. 1 that fixes seed generation for future wallets but explicitly warned the update cannot add entropy to or secure seeds already created on affected builds, so users must migrate funds to new seeds made on updated devices.
  • The incident has driven a rush of migrations that distorted on‑chain metrics, prompted Galaxy and other firms to report suspected attacker clusters to investigators, and renewed debate over the operational risks of self‑custody versus institutional custody.