Coldcard Flaw Drains $70M in Bitcoin in 41 Minutes
A critical firmware vulnerability in Coldcard hardware wallets enabled attackers to steal over $70 million in Bitcoin. The flaw stemmed from a 2021 PRNG implementation error.
TL;DR
- Attackers stole 1,082 BTC (~$70.2M) from 1,196 addresses in 41 minutes.
- Galaxy Research linked the theft to a Coldcard firmware vulnerability.
- The flaw originated from a March 2021 update involving a weak PRNG.
- Coldcard is a Bitcoin-only hardware wallet by Coinkite.
- Organizations should audit third-party crypto integrations for RNG flaws.
In a stunning 41-minute window, threat actors exploited a firmware vulnerability in Coldcard hardware wallets to steal approximately $70.2 million in Bitcoin. The incident, which targeted 1,196 addresses, was traced back to a flawed pseudorandom number generator introduced in a 2021 firmware update.
Security researchers at Galaxy Research confirmed the breach and highlighted how the deterministic nature of the compromised PRNG made private key prediction possible. This high-profile case underscores the critical importance of secure randomness in cryptographic implementations, especially in financial applications.
Vulnerability Details
- The flaw was introduced in March 2021 via a firmware update that used a deterministic software PRNG instead of secure hardware-based entropy.
- This weakness allowed attackers to predict private keys generated by affected devices.
- Only wallets created after the flawed firmware release were at risk.
- Coinkite has since patched the issue and advised users to upgrade immediately.
Impact and Lessons Learned
- Total loss exceeded $70 million across 1,196 Bitcoin addresses.
- The speed of the attack highlights the automation capabilities of modern crypto thieves.
- Organizations integrating third-party hardware or firmware must validate cryptographic implementations.
- Random number generation is a frequent target—ensure all RNGs meet industry standards like FIPS 140-2.
- Incident response plans should include rapid patch deployment and user communication protocols.
Sources
Sources
Security email updates
One digest email when we publish new security articles (TL;DR plus links to read more). Unsubscribe anytime from the message footer. See our Privacy Policy.