Coldcard Wallet PRNG Flaw Leads to $86M Bitcoin Loss
Key Facts
Amid growing reliance on self-custody solutions for digital assets, a critical security vulnerability in Coldcard hardware wallets has resulted in massive losses. According to reports, a flaw in the firmware's pseudo-random number generator (PRNG) led to the theft of 1,367 Bitcoin, valued at approximately $86 million. This silent exploit persisted over a five-year period, raising significant concerns regarding the security standards of cold storage devices.
The vulnerability was caused by a misconfigured macro within the firmware, which resulted in insufficient entropy for generated seed phrases. This technical failure meant that the private keys were not as random as required for robust security. Data indicates that the flaw impacted 4,585 specific wallet addresses, allowing attackers to exploit the weakened encryption and drain funds over several years.
This news arrives at a sensitive time for the crypto market, as investors closely monitor cybersecurity developments and their impact on user trust in hardware wallets.