Coldcard Wallet Flaw Exposes Years Of Bitcoin Seeds After $70M In BTC Stolen

The popular Bitcoin hardware wallet Coldcard product, made by Coinkite, is at risk following a $70 million hack.

Coinkite on Thursday admitted that its Coldcard Mk3 model was affected following the hack and advised users to move their funds. Then, on Friday, the company said that users of the later hardware devices Mk4, Mk5, and Q should also take precautions. 

Hackers on Thursday were first able to drain funds from 1,196 Bitcoin addresses because their private keys were not generated using sufficient entropy — or randomness. 

Read More:  Cantor SPAC And Adam Back's Bitcoin Treasury Renegotiate Merger Terms, Vow New Structure

Since then, a total of 1,082.65 Bitcoins have disappeared from wallets, according to data from Galaxy Research and engineers at payments company Block. 

While Coinkite has not admitted that the hack is linked to their wallets, the company has said that a wallet seed generation bug in Coldcard products meant the hardware’s true random number generator wasn’t actually being used on certain firmware versions. 

Read More:  Strategy (MSTR) Surges 12% As Bitcoin Regains $60,000

Coinkite and other engineers in the Bitcoin space are still investigating reportedly ongoing drains still happening at the time of writing.

What actually happened 

A firmware bug in Coldcard Mk3 devices (starting with version 4.0.1 in March 2021) caused seed generation to fall back to a weak software PRNG instead of the hardware true random number generator, producing seeds with only ~40 bits of entropy rather than the intended 128.  This made private keys for many single-signature wallets (especially those created without dice rolls or a strong BIP-39 passphrase) predictable enough for attackers to brute-force.

Read More:  Russia's Sberbank Sets December Deadline For Crypto Buildout

A total of 594.5 Bitcoins worth over $35.7 million at today’s prices were moved to a new address from single-signature addresses on Thursday.