Coldcard Exploit: $70 Million in Bitcoin Drained Following Firmware Flaw
Key Facts
In a dramatic escalation of the security crisis surrounding Coldcard wallets, recent reports confirm that an actual exploit has occurred, leading to a massive drain of user assets. According to reports, $70 million worth of Bitcoin (BTC) was stolen from 1,196 wallets linked to the previously identified firmware vulnerability. This development marks a critical shift from a theoretical risk warning to a realized financial loss affecting a significant number of holders.
Data from Galaxy indicates that attackers successfully exploited the flaw in random number generation, which compromised the cryptographic integrity of Coinkite's hardware. The scale of the theft far exceeds earlier estimates of assets at risk, placing unprecedented pressure on the reputation of cold storage solutions. Per market data, the success of this exploit raises fundamental questions regarding the security standards maintained in hardware wallet manufacturing.
Investors are awaiting further official responses from Coinkite regarding potential restitution or emergency security patches. Additionally, U.S. New Home Sales data in the economic calendar remains a key catalyst for broader liquidity trends in the digital asset market.
Latest Updates · 4
- Major·
Update: Investigations reveal the security flaw dates back to a March 2021 firmware update, which rendered seed phrases guessable. This vulnerability has already resulted in the theft of $38 million from approximately 500 wallets, highlighted by a rapid exploit where 594 BTC were drained in a mere 25-minute window.
- Notable·
Update: Subsequent technical reports revealed that the exploit was a fully automated attack targeting more than 500 Bitcoin addresses simultaneously. In light of this, expert Peter Todd warned against the continued use of single-signature (Singlesig) wallets, emphasizing the urgent need for more robust security frameworks to counter such programmed threats.
- Notable·
Update: Coinkite has issued an urgent call for Coldcard Mk3 users to migrate their Bitcoin if recovery seeds were generated on affected firmware versions. Meanwhile, security researchers identified a coordinated transfer of 594.48 BTC valued at approximately $38.2 million; while no direct link to the flaw is confirmed, the movement has heightened market vigilance.
- Notable·
Update: New details reveal the exploit was highly coordinated, draining approximately 500 individual wallets within a mere 25-minute window. Furthermore, Coinkite has issued a specific warning to Mk3 owners, stating that any seeds generated since March 2021 may be compromised due to predictability issues in the generation process.