Coldcard Wallet Flaw Exposes $130 Million in Bitcoin as Hackers Reconstruct Private Keys

· · Views: 2,245 · 3 min time to read

A security flaw in supposedly offline Coldcard hardware wallets has allowed multiple hackers to steal approximately $130 million in Bitcoin, undermining one of cryptocurrency’s most widely promoted methods of protecting digital assets.

At least a dozen attackers were targeting Bitcoin owners who used Coldcard devices manufactured by Canadian company Coinkite.

Attackers Did Not Need Physical Access

Cold wallets are designed to keep the recovery phrase controlling a person’s Bitcoin away from internet-connected devices. However, the Coldcard incident shows that offline storage can still fail when the process used to create the secret information is predictable.

TechCrunch reported that hackers exploited a flaw in how some Coldcard wallets generated recovery seed phrases, allowing the attackers to calculate possible phrases through brute-force methods.

CryptoSlate said the vulnerability originated in Coldcard firmware dating to March 2021, when a coding error caused certain devices to rely on a weaker software process instead of drawing enough randomness from the hardware random-number generator. The reduced number of possible seed combinations allowed attackers to reconstruct private keys remotely without obtaining either the physical wallet or its written recovery words.

Thousands of Addresses Linked to Attack Waves

CryptoSlate reported that Galaxy Research had confirmed the theft of 1,596 Bitcoin from approximately 7,300 addresses across three large attack waves and 14 smaller incidents. A possible fourth wave could increase the total to 2,055 Bitcoin, valued at about $130 million, although Galaxy excluded those addresses from its confirmed estimate while awaiting additional victim reports.

Elliptic co-founder and chief scientist Tom Robinson considered the roughly $130 million estimate accurate. The report also cited victim Jonathan Goodman, who said $1.6 million was stolen despite keeping his devices offline and storing them in safes and safety-deposit boxes.

Firmware Update Alone Cannot Protect Existing Wallets

Installing updated firmware prevents a Coldcard device from generating another weak seed but cannot repair a recovery phrase already created through the vulnerable process. Coinkite has urged users to update their devices, generate completely new recovery phrases and transfer their Bitcoin to addresses derived from the secure seeds.

TechCrunch also reported that Coinkite advised customers to update and “migrate” their funds after disclosing the flaw in a security advisory.

Emergency Transfers Create New Phishing Risks

The rush to protect remaining funds has produced unusually high activity across the Bitcoin network.

Active Bitcoin addresses reached 712,000 over seven days, the highest level in three months, while transactions worth more than $100,000 climbed to 61,800, a five-month high. Transactions waiting for confirmation increased from around 33,000 to approximately 96,000 as users moved funds from potentially exposed wallets.

Rival wallet manufacturer Trezor warned that criminals were sending fraudulent migration instructions and impersonating support teams in an effort to obtain recovery words.

The Coldcard breach demonstrates that self-custody depends not only on keeping a device offline, but also on trusting the software and hardware that create its private keys. A wallet can remain physically secure while the mathematical secret protecting it has already become vulnerable.

Share
f 𝕏 in
Copied