← Back to blog

Coldcard Flaw Drains $70M in Bitcoin in 41 Minutes

A critical firmware vulnerability in Coldcard hardware wallets enabled attackers to steal over $70 million in Bitcoin. The flaw stemmed from a 2021 PRNG implementation error.

TL;DR

  • Attackers stole 1,082 BTC (~$70.2M) from 1,196 addresses in 41 minutes.
  • Galaxy Research linked the theft to a Coldcard firmware vulnerability.
  • The flaw originated from a March 2021 update involving a weak PRNG.
  • Coldcard is a Bitcoin-only hardware wallet by Coinkite.
  • Organizations should audit third-party crypto integrations for RNG flaws.

In a stunning 41-minute window, threat actors exploited a firmware vulnerability in Coldcard hardware wallets to steal approximately $70.2 million in Bitcoin. The incident, which targeted 1,196 addresses, was traced back to a flawed pseudorandom number generator introduced in a 2021 firmware update.

Security researchers at Galaxy Research confirmed the breach and highlighted how the deterministic nature of the compromised PRNG made private key prediction possible. This high-profile case underscores the critical importance of secure randomness in cryptographic implementations, especially in financial applications.

Vulnerability Details

  • The flaw was introduced in March 2021 via a firmware update that used a deterministic software PRNG instead of secure hardware-based entropy.
  • This weakness allowed attackers to predict private keys generated by affected devices.
  • Only wallets created after the flawed firmware release were at risk.
  • Coinkite has since patched the issue and advised users to upgrade immediately.

Impact and Lessons Learned

  • Total loss exceeded $70 million across 1,196 Bitcoin addresses.
  • The speed of the attack highlights the automation capabilities of modern crypto thieves.
  • Organizations integrating third-party hardware or firmware must validate cryptographic implementations.
  • Random number generation is a frequent target—ensure all RNGs meet industry standards like FIPS 140-2.
  • Incident response plans should include rapid patch deployment and user communication protocols.

Sources

Sources

Security email updates

One digest email when we publish new security articles (TL;DR plus links to read more). Unsubscribe anytime from the message footer. See our Privacy Policy.

Coldcard Flaw Drains $70M in Bitcoin in 41 Minutes — Agent Breach Blog | Agent Breach