Urgent.News

What's breaking now, across thousands of outlets.

Science

Coldcard Hardware Wallet Flaw Linked to $70 Million Bitcoin Theft in 41 Minutes

An attacker drained 1,196 Bitcoin addresses in 41 minutes on July 30, taking 1,082.65 BTC worth about $70.2 million at the time. Galaxy Research mapped the sweep and tied it to a firmware flaw in Coldcard, the Bitcoin-only hardware wallet made by Canadian firm Coinkite. A March 2021 firmware integration error routed seed generation to a deterministic software pseudorandom number generator (PRNG

Coldcard Hardware Wallet Flaw Linked to $70 Million Bitcoin Theft in 41 Minutes

A security breach has been uncovered in Coldcard hardware Bitcoin wallets, resulting in the theft of $75 million. Hardware wallets are typically considered the most secure method for storing Bitcoin, as they are not connected to the internet and all keys remain on the device. However, a flaw in Coldcard's firmware, which was introduced on March 1, 2021, allowed attackers to easily guess the recovery seed used to secure these wallets.

The recovery seed is intended to be generated by a hardware random number generator, providing 128 bits of entropy, making it nearly impossible to guess. However, due to a single code change, the firmware on Coldcard Mk3 devices fell back to a software-based generator, collapsing the search space to just 40 bits. This significant reduction in entropy makes it feasible for attackers to brute-force the recovery seed, effectively turning the hardware wallet into a vulnerable point.

Within minutes of discovering the vulnerability, the attacker began targeting wallets with the largest balances, moving over $30 million in the first ten minutes alone. By 25 minutes, approximately 594 BTC had been transferred from around 500 single-signature wallets. One victim reportedly lost $1.8 million worth of Bitcoin.

To address the issue, Coinkite, the manufacturer of Coldcard, released a fixed firmware update. However, it is crucial to note that updating the hardware does not repair existing weak seeds. Affected users must generate new wallets on updated hardware and transfer their funds to these secure wallets. As of Saturday morning, Galaxy Research had tracked a total of 1,158.66 BTC (about $75.1 million) stolen from 2,673 addresses.

The security breach is ongoing, and users are strongly advised to immediately move their Coldcard single-signature funds to safer locations. Investigators have been alerted to nearly 600 addresses believed to be holding stolen funds, and they urge federal investigators, industry compliance firms, and cross-industry cyber investigators to closely monitor these funds.

Written by urgent.news from Slashdot's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.

This story

This is one outlet's version. Read the fullest account.

Read the original at thehackernews.com →

More in Science

More from Saturday 1 August →