Coldcard Cold Wallet Heist: $70M Stolen Without Touching Devices – Here's How
Coindesk1 hour ago
870

Coldcard Cold Wallet Heist: $70M Stolen Without Touching Devices – Here's How

Technology
coldcard
bitcoin
security
hardwarewallet
exploit
Share this content:

Summary:

  • Over 1,000 BTC stolen from 1,196 Coldcard wallets in a 41-minute window without touching devices.

  • Attack exploited weak seed generation due to a firmware flaw, reducing key space to ~4 billion possibilities.

  • Attackers used systematic enumeration across three address formats, indicating a scanner, not targeted theft.

  • Victims cannot easily determine if they are exposed, and further attacks are likely if funds aren't moved.

  • Investigators traced the attacker via blockchain data provider logs, aiding law enforcement.

A sophisticated attack drained over 1,000 BTC (worth ~$70 million) from 1,196 Coldcard hardware wallets in just 41 minutes on July 30, 2026. The theft didn't involve physical access or malware – instead, attackers exploited a critical firmware flaw that allowed them to reconstruct private keys offline.

The Vulnerability: Weak Seed Generation

Coldcard wallets are designed to generate seed phrases using a dedicated hardware randomness generator. However, an internal build setting skipped this generator, and a supporting library only checked if the setting existed, not if it was enabled. This caused key generation to fall back to a basic software substitute seeded from the chip's serial number and clock registers.

This reduced the possible key space from astronomically large to a computationally enumerable range. For Mk4, Q, and Mk5 models, attackers could brute-force through roughly 4 billion possibilities – a trivial task for modern computers.

The Attack: Systematic Enumeration

The attacker generated candidate seeds on their own hardware, derived addresses, and checked them against the public blockchain. This process ran entirely on the attacker's machine, meaning victims' devices were never involved and could be powered off in safes.

Galaxy Research's analysis revealed the attack swept funds across three address formats (native segwit, older standards), indicating a systematic scanner rather than targeted theft. The funds now sit in four addresses and remain unmoved.

The Aftermath: Uncertainty and Ongoing Risk

Coinkite (Coldcard's maker) initially warned Mk3 owners, but Block's report also implicates Mk2, Mk4, Q, and Mk5. Owners cannot easily determine if their seeds were generated on vulnerable firmware, leaving many in limbo.

Investigators found a crucial mistake: the attacker used a paid account at a blockchain data provider, whose logs matched the suspicious queries with "extraordinary specificity." This information has been passed to authorities.

The Bigger Picture: Cold Storage Isn't Bulletproof

This incident challenges the core promise of hardware wallets – that keys are unguessable. As computational power grows, even supposedly secure devices can be compromised without physical access. The attack underscores the need for rigorous firmware auditing and post-quantum cryptography to future-proof digital assets.

For now, affected users are urged to move their funds to wallets with freshly generated seeds, as further waves of attacks are likely.

Comments

0

Join Our Community

Sign up to share your thoughts, engage with others, and become part of our growing community.

No comments yet

Be the first to share your thoughts and start the conversation!

Newsletter

Subscribe our newsletter to receive our daily digested news

Join our newsletter and get the latest updates delivered straight to your inbox.

BitcoinToday.app logo

BitcoinToday.app

Get BitcoinToday.app on your phone!