Ongoing Risk After $89 Million in Bitcoin Drained @COLDCARDwallet maker Coinkite has issued a high-priority security alert, urging all users to immediately migrate their $BTC holdings and gen
Ongoing Risk After $89 Million in Bitcoin Drained
@COLDCARDwallet maker Coinkite has issued a high-priority security alert, urging all users to immediately migrate their $BTC holdings and generate entirely new recovery seeds. The warning comes after a firmware vulnerability led to one of the most damaging self-custody exploits in Bitcoin history.
A third wave of thefts, flagged by Galaxy Research on August 2, pushed the running total to 1,367 BTC, roughly $89 million, drained from 4,585 addresses.The initial sweep saw an attacker drain 1,196 Bitcoin addresses in just 41 minutes on July 30, with Galaxy Research tying the theft to a firmware flaw in Coldcard, the Bitcoin-only hardware wallet made by Canadian firm Coinkite.
A March 2021 firmware integration error routed seed generation to a deterministic software pseudorandom number generator (PRNG) instead of the STM32 hardware random number generator (RNG).On Mk3 devices, the effective search space collapsed to roughly 40 bits, far below the 128-bit entropy expected from a secure hardware wallet. Researchers say the flaw made supposedly unguessable seed phrases computationally enumerable, allowing attackers to reconstruct private keys without ever touching the devices.
What Users Must Do Now
Coinkite shipped emergency firmware for every affected model and release track on July 31, but installing it does not repair an existing seed. That means a firmware upgrade alone is not sufficient. Users must also generate entirely new seeds on updated devices.
The underlying weakness remains exploitable for any seed still holding funds that was generated during the vulnerable period, and attackers with knowledge of the flaw can continue targeting addresses whose public keys or xpubs have been exposed.
Users who generated a seed on a Coldcard device after March 2021, did not use the dice-roll feature with at least 50 rolls during seed generation, and do not have an additional BIP-39 passphrase should consider their seed words vulnerable and at risk, and must migrate their coins to a new and safe wallet as soon as possible.
The exploit appears limited to Coldcard products and does not impact other hardware wallet vendors such as Ledger, Trezor, or Bitkey. Coldcard has advised users to approach any migration with care, warning that rushing the process introduces its own risks.
Sources:CoinDesk: How Bitcoin cold wallets lost $70 million in an attack that never touched the devicesThe Hacker News: Coldcard Hardware Wallet Flaw Linked to $70 Million Bitcoin Theft in 41 MinutesTheStreet Crypto: Coldcard hack losses grow to $89 million across three waves