How a hidden flaw in Coldcard wallets led to an $88.6m Bitcoin theft
Coldcard is a hardware wallet aimed at serious Bitcoin users. It only supports Bitcoin, can be kept offline and uses open-source software. It is assembled in Canada and is designed to keep users' Bitcoin secure. But from March 2021, some Coldcard devices generated customers' private keys using the device's serial number and its internal clock, rather than the dedicated chip designed to produce…
In March 2021, a flaw in Coldcard hardware wallets caused Bitcoin thefts totaling $88.6 million. The vulnerability caused the wallets to generate private keys using the device's serial number and internal clock, rather than through a secure random number generator. This made the keys easy to predict. In July 2021, an attacker stole 594 Bitcoin from around 500 inactive wallets in just 25 minutes.
The theft was later linked to 1,082 Bitcoin across 1,196 addresses. Coinkite, the Canadian company behind Coldcard, has acknowledged the flaw and the resulting theft.
Written by urgent.news from The National UAE's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.
Also reported by 1 other outlet
- How a hidden flaw in Coldcard wallets led to an $88.6m Bitcoin theft thenationalnews.com