Coldcard firmware flaw drains 594 bitcoin from wallets
An attacker swept 594 bitcoin, worth roughly $38 million at the time, from about 500 single-signature Coldcard wallets in a 25-minute window, exploiting a firmware bug that caused affected devices to bypass their dedicated hardware random number generator in favour of a weak software substitute. By the end of the day, Galaxy Research put the value of wallets exposed to the same flaw at closer to $70 million, as more affected addresses came to light.
The bug produced seed phrases with roughly 40 bits of entropy rather than the intended 128, making them guessable, and had gone unnoticed since March 2021. Coinkite, which makes Coldcard, said the risk is limited to Mk3 devices running firmware version 4.0.1 or later; the Mk4, Q and Mk5 lines are not affected. Chief executive Rodolfo Novak apologised publicly, writing "I'm sorry and I'm devastated," and said the company was taking full responsibility for the failure.
A random number generator is the one component a hardware wallet cannot get wrong without undoing everything else the device is built to protect.