594 BTC Drained in 25 Minutes: Coldcard Firmware Flaw Exposes 500 Wallets

Key Takeaways

A critical firmware defect in Coldcard hardware wallets enabled the theft of 594 BTC from 500 dormant accounts. The vulnerability, rooted in a 2021 code commit, compromised key generation by substituting true randomness with predictable serial numbers.

Woofun AI reports that a sophisticated sweep operation extracted approximately 594 bitcoin, valued at roughly $38 million, from an estimated 500 distinct wallets over a compressed 25-minute interval on Friday. This incident, which unfolded between 01:31 and 01:56 UTC, has been directly attributed to a fundamental flaw in the cryptographic key generation process of Coldcard hardware wallets, devices manufactured by the Canadian firm Coinkite. The attack vector exploited a specific weakness identified by Block, the parent company of Bitcoin engineering and security teams, revealing how a legacy code error could be leveraged to compromise offline storage solutions that are typically considered secure against internet-based threats. The precision of the timing and the scale of the extraction suggest a targeted campaign rather than opportunistic theft, highlighting the severe risks inherent in hardware wallet firmware vulnerabilities.

The transactional footprint of the attack was both rapid and highly structured, moving 1,324 individual chunks of bitcoin across 500 separate transactions within a narrow three-block window. Following this initial dispersion, 562 BTC were consolidated into a single address that has remained static since the transfer, indicating a staging area for further laundering or long-term holding. Every wallet targeted in this operation was a single-signature account, and each contained a balance exceeding 0.

15 BTC, suggesting that attackers employed automated scanning tools to identify viable targets based on minimum threshold criteria. The stolen coins originated from wallets created between 2021 and 2026, a timeframe that aligns almost perfectly with the lifespan of the vulnerable firmware version, implying that the attackers had mapped the exposure window with significant accuracy. The dormancy of many of these accounts for years prior to the breach further underscores the latent danger of unpatched legacy systems in the Bitcoin ecosystem.

Woofun AI data shows that Coldcard's product lineage includes the Mk2, Mk3, Mk4, Q, and Mk5 models, which represent successive generations of hardware released over several years in a manner analogous to consumer electronics manufacturers shipping numbered iterations.

However, the critical factor determining exposure was not the physical model or the purchase date of the device, but rather the specific firmware version running at the precise moment the wallet’s seed was generated. The seed, a secret phrase that controls access to the funds, is theoretically derived from a pool of entropy so vast that brute-force guessing is computationally impossible. In this case, the firmware failed to execute this randomization correctly, rendering the security model ineffective for devices initialized under the flawed conditions. This distinction between hardware generation and software state is crucial for users assessing their risk, as newer physical models could still be vulnerable if initialized with older, compromised firmware versions.

The technical root cause was traced by Block’s Bitcoin engineering and security teams to a build setting that inadvertently instructed the device to bypass its dedicated hardware randomness generator. A check within a supporting library verified only the existence of this setting rather than its active status, causing key generation to fall back on a basic software substitute seeded by the chip’s serial number and clock registers.

Neither the serial number nor the clock values constitute cryptographic secrets; the former is fixed factory metadata, while the latter represents timing state that can be narrowed or measured by an attacker using their own device. Block identified the origin of this change in a commit dated March 1, 2021, which was shipped in firmware 4.0.0 that same month. Consequently, Coinkite warned users who generated a seed on an Mk3 running version 4.0.

1 or later, while explicitly stating that "Mk4, Q and Mk5 are not affected" by this specific vulnerability, providing a clear boundary for remediation efforts.

The scope of the exposure extends beyond standard wallet seeds, as the same compromised generator was used to produce Coldcard’s paper wallet private keys, where the output serves directly as the key without further derivation.

Additionally, seed-splitting masks, device cloning keys, and Key Teleport transfers were all generated using this flawed entropy source, amplifying the potential attack surface for users relying on these advanced features. Block disclosed its findings to Coinkite, whose team acknowledged the issue, though both companies describe their analyses as preliminary, with Block publishing the report without full exploitability testing because the exploitation was already underway. Despite the significant volume of stolen assets, Bitcoin traded above $64,000 in early Asian hours, with the widespread drain appearing to have little immediate impact on the broader market sentiment. This resilience suggests that while individual security failures can be catastrophic for victims, the systemic stability of the network remains largely unaffected by isolated firmware breaches.

Comments

Me
Replying to @User
0/800

No comments yet.

Notifications

Sign in to view messages
View all messagesManage subscriptions