Vulnerability Management

Coldcard hardware wallet firmware flaw led to $70 million Bitcoin theft

Golden bitcoin cryptocurrency on computer circuit board

A firmware flaw in Coldcard hardware wallets, a Bitcoin-only device, has been linked to the draining of 1,196 Bitcoin addresses in just 41 minutes on July 30, resulting in the theft of approximately $70.2 million worth of Bitcoin. The issue stems from a March 2021 firmware integration error that incorrectly routed seed generation, as reported by The Hacker News.

The vulnerability, identified by Block and detailed by Galaxy Research, occurred because a deterministic software pseudorandom number generator (PRNG) was used instead of the intended hardware random number generator (RNG) for seed generation. This error allowed an attacker, under specific conditions, to reproduce candidate output streams offline. By checking these candidate seeds against public blockchain data, the attacker could identify and drain vulnerable addresses. Coinkite, the manufacturer of Coldcard, has released emergency firmware updates for all affected models and release tracks. However, installing the new firmware does not repair seeds already exposed by the flaw.

Coinkite advises users whose seeds may have been compromised to generate a new seed on the patched firmware and move their funds immediately. Restoring an old seed, even to updated firmware, carries the weakness forward. The extent of the vulnerability depends on the firmware version running when the seed was created, with specific versions of Mk2, Mk3, Mk4, Mk5, and Q models being affected. While no attacker has been publicly named, the pattern of the sweep has been mapped, though it mimics legitimate coin movement.

Source: The Hacker News

Related Events

Get daily email updates

SC Media's daily must-read of the most current and pressing daily news

By clicking the Subscribe button below, you agree to SC Media Terms of Use and Privacy Policy.

You can skip this ad in 5 seconds