Loading IndicatorLoading Indicator

Coldcard Left Seed-Generation Firmware Bug Unfixed for Four Years, Leading to $100 Million Bitcoin Theft

Source
Minseung Kang

Summary

  • Galaxy Research said 1,596 Bitcoin were stolen from about 7,300 addresses through a Coldcard wallet vulnerability.
  • A bug in Coinkite's firmware 4.0.0 caused a predictable software generator to be used instead of a hardware random-number generator during seed creation.
  • Coinkite distributed patched firmware, but it cannot protect previously vulnerable seeds and advised users to create a new seed and move their Bitcoin.

Forecast Trend Report by Period

Loading IndicatorLoading Indicator
Photo: Shutterstock
Photo: Shutterstock

A flaw in the seed-generation code of Coldcard hardware wallets went unaddressed for years and ultimately led to a major cryptocurrency theft, CoinDesk reported.

Citing Galaxy Research, CoinDesk reported on Aug. 17 that 1,596 Bitcoin worth more than $100 million were stolen from about 7,300 addresses. Alex Thorn, head of research at Galaxy, estimated that at least 15 attackers exploited the vulnerability and said the attacks could be carried out without physical access.

The flaw centered on how the wallet generated seeds. Firmware version 4.0.0, released by Coldcard maker Coinkite in March 2021, contained an error in code that reads random-number generator settings. The code checked only whether a settings entry existed, not whether it was actually enabled. That led the wallet to use a more predictable software generator instead of a higher-security hardware random-number generator.

Bitcoin developer James O'Beirne reported the potential defect to Coinkite during a code audit in May 2025. Coinkite effectively dismissed the report, saying that if it had been a real problem, it would already have been discovered. The code was open source, but outside reviewers also missed the error because they did not trace the entire seed-generation process to the end. An artificial intelligence-based code review Coinkite conducted before and after the incident also failed to detect the flaw.

Coinkite has distributed patched firmware for all affected Coldcard models. The update only ensures the safety of seeds generated in the future and does not protect seeds that were already created using the vulnerable firmware. Coinkite is advising affected users to install the patched firmware, generate a new seed and move Bitcoin from old addresses to new ones.

#Cold Wallet
#Hacking
Minseung Kang

Minseung Kang

minriver@bloomingbit.ioBlockchain journalist | Writer of Trade Now & Altcoin Now, must-read content for investors.

What do you think about this news?








PiCK News






Hashtag News