How a hidden flaw in Coldcard wallets led to an $88.6m Bitcoin theft
Coldcard is a hardware wallet aimed at serious Bitcoin users. It only supports Bitcoin, can be kept offline and uses open-source software. It is assembled in Canada and is designed to keep users' Bitcoin secure. But from March 2021, some Coldcard devices generated customers' private keys using the device's serial number and its internal clock, rather than the dedicated chip designed to produce…
Coldcard is a hardware wallet that caters to serious Bitcoin users. It is designed to operate offline and utilizes open-source software. Assembled in Canada, it is intended to keep users' Bitcoin secure. However, from March 2021, certain Coldcard devices started generating private keys using the device's serial number and internal clock, as opposed to a dedicated chip meant for generating random numbers.
This flaw made the keys more susceptible to prediction. On July 30, an attacker managed to steal 594 Bitcoin from approximately 500 dormant wallets within a span of just 25 minutes. Galaxy Research later traced the larger theft to 1,082 Bitcoin across 1,196 addresses, which had increased to nearly 1,367 Bitcoin by August 2. This amounted to around $88.6 million.
The attacker did not require physical access to the wallets. The publicly available Coldcard software code and information on the Bitcoin blockchain enabled the attacker to spend several weeks working out the possible keys that the faulty software could have produced. They then matched these keys with Bitcoin addresses holding funds.
Once the compromised wallets were identified, the attacker proceeded to transfer the Bitcoin. The theft itself was completed in just 25 minutes. The flaw in question is more alarming than the term "bug" implies. Coldcard distrusts the general-purpose randomness within the software it is built upon, so it incorporates the chip's hardware generator and disables the built-in one.
However, a safety check in a supporting library failed to detect that the built-in generator had been disabled. Consequently, seed generation bypassed the software fallback, which obtained whatever randomness it could from the serial number and clock, without generating new randomness. A seed is intended to hold 128 bits of entropy.
On the Mk3 version, it only contained about 40. In physical terms, a lock manufacturer may claim a million combinations, but a factory defect could result in a production run only having access to about a thousand of them. The lock still functions and appears identical to other locks on the shelf. The owner has no way of knowing.
The thief only needs to know which thousand possibilities exist. The underlying mathematics of elliptic curves has never been broken. The randomness feeding them was. The scope of the vulnerability extends beyond the stolen coins. A seed is not a Bitcoin object; it is merely entropy. It can also generate addresses and keys for other systems.
If an individual used a Coldcard seed in a multi-chain wallet, they were employing the same flawed dice at a different table. Coinkite, the Canadian firm behind the device, has provided its own account of the incident. A few weeks prior to the theft, the company ran an advanced AI model over the code, searching for security issues.
The review came back clean. The company also believes that the attacker discovered the flaw by examining the open-source firmware. Both parties had access to the same tools. The AI-assisted security was able to detect vulnerabilities in one instance but not in the other. This incident highlights the challenges of AI-assisted security, as the defender seeks a model to spot every serious vulnerability, while the attacker only needs to find one exploitable path.
The mantra "not your keys, not your coins" underscores the importance of self-custody. When individual keys are mishandled, recovery becomes extremely difficult, as Bitcoin is a bearer instrument. Whoever can produce a valid signature can move the coin. The network does not differentiate between the owner and the attacker. The process of recovery involves identifying the person in a jurisdiction willing to hear the case and proving the wallet was yours, and that the transfer was unauthorized.
This can be a daunting and costly endeavor. In the case of Coldcard, a regulated custodian may be the only entity that can be made to pay, as they have insurance, contractual liability, auditors, and regulators on their side. However, this choice was made based on a slogan, and it is essential to recognize that the failure was not limited to one vendor's build pipeline.
Every user who supplied their own dice rolls during setup remained unaffected. The key takeaway is that self-custody transfers responsibility. The crucial question is not merely who holds your keys, but who bears the loss when those keys fail.
Written by urgent.news from The National Business's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.
This story
This is one outlet's version. Read the fullest account.
- How a hidden flaw in Coldcard wallets led to an $88.6m Bitcoin theft thenationalnews.com