A significant security breach involving Coldcard hardware wallets has resulted in the loss of 1,082.65 Bitcoin, valued at approximately $70.2 million at the time of the incident. On July 30, a malicious actor successfully compromised 1,196 individual addresses within a 41-minute window, sparking an investigation into the integrity of the device firmware.
Research conducted by Galaxy Research traced the source of the compromise to a critical error introduced in a March 2021 firmware update. According to The Hacker News, this specific integration error inadvertently directed the device's seed generation process toward a deterministic software-based pseudorandom number generator (PRNG). By bypassing the intended hardware-level randomness, the flaw made the private keys predictable, allowing the perpetrator to reconstruct user wallets and extract the funds with precision.
The scale and speed of the operation suggest a highly coordinated effort to exploit legacy vulnerabilities in hardware security modules. As users and security professionals evaluate the fallout, the incident underscores the inherent risks associated with firmware updates that modify fundamental cryptographic processes. Coinkite, the manufacturer behind Coldcard, faces increased scrutiny as investigators analyze how a flaw of this nature remained undetected within the Bitcoin-only hardware ecosystem for several years.
Reader Discussion & Insights