Binance founder CZ calls for wallet diversification after $70 million Coldcard exploit
Binance founder Changpeng Zhao says hardware wallets can still have bugs and suggests spreading funds across multiple wallets after the major Coldcard security failure.
A security breach has been uncovered in Coldcard hardware Bitcoin wallets, resulting in the theft of $75 million. Hardware wallets are typically considered the most secure method for storing Bitcoin, as they are not connected to the internet and all keys remain on the device. However, a flaw in Coldcard's firmware, which was introduced on March 1, 2021, allowed attackers to easily guess the recovery seed used to secure these wallets.
The recovery seed is intended to be generated by a hardware random number generator, providing 128 bits of entropy, making it nearly impossible to guess. However, due to a single code change, the firmware on Coldcard Mk3 devices fell back to a software-based generator, collapsing the search space to just 40 bits. This significant reduction in entropy makes it feasible for attackers to brute-force the recovery seed, effectively turning the hardware wallet into a vulnerable point.
Within minutes of discovering the vulnerability, the attacker began targeting wallets with the largest balances, moving over $30 million in the first ten minutes alone. By 25 minutes, approximately 594 BTC had been transferred from around 500 single-signature wallets. One victim reportedly lost $1.8 million worth of Bitcoin.
To address the issue, Coinkite, the manufacturer of Coldcard, released a fixed firmware update. However, it is crucial to note that updating the hardware does not repair existing weak seeds. Affected users must generate new wallets on updated hardware and transfer their funds to these secure wallets. As of Saturday morning, Galaxy Research had tracked a total of 1,158.66 BTC (about $75.1 million) stolen from 2,673 addresses.
The security breach is ongoing, and users are strongly advised to immediately move their Coldcard single-signature funds to safer locations. Investigators have been alerted to nearly 600 addresses believed to be holding stolen funds, and they urge federal investigators, industry compliance firms, and cross-industry cyber investigators to closely monitor these funds.
Written by urgent.news from Slashdot's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.
This story
This is one outlet's version. Read the fullest account.
- Coldcard Hardware Wallet Flaw Linked to $70 Million Bitcoin Theft in 41 Minutes thehackernews.com
- Recovery Seeds Reportedly Breached for Coldcard Hardware Bitcoin Wallets, $75M Taken it.slashdot.org
- Bitcoin hardware wallet Coldcard shipped a faulty firmware build, and hackers are now draining wallets; Galaxy Research estimates $70M+ stolen (Shaurya Malwa/CoinDesk) coindesk.com
- Coldcard Bitcoin loss estimate rises to $70M after Galaxy analysis cointelegraph.com