Web3: Coldcard wallet vulnerability leads to the theft of 594 bitcoins.
CoinDesk
5h ago
Ai Focus
Coldcard hardware wallets were found to have a key generation flaw, allowing attackers to steal approximately 594 bitcoins within 25 minutes.
Helpful
No.Help

Canadian hardware wallet maker Coinkite's Coldcard has been found to have a key generation flaw. Attackers exploited this vulnerability to transfer 594 bitcoins in approximately 25 minutes, estimated at around $38 million based on the price mentioned in the article. About 500 addresses were affected, all of which are single-signature wallets.

Transfer out within 25 minutes

On-chain records show that the funds were rapidly transferred out between 01:31 and 01:56 UTC on Friday. The relevant transfers were distributed across 3 blocks, involving a total of 500 transactions and 1324 Bitcoins.

Of these, 562 bitcoins were subsequently consolidated into a single address and had not been transferred further as of the time of this report. The emptied wallets all shared a common characteristic: they were all single-signature addresses, and each wallet held more than 0.15 bitcoins.

Many of the addresses have not been used for many years, and the funds were formed between 2021 and 2026, a timeframe that largely coincides with the period when the vulnerability existed.

The vulnerability stems from a failure in random number generation.

The problem lies in Coldcard's random number generation process when generating wallet seeds. By design, wallet seeds should come from a highly random source that is difficult to predict, but a report released by Block's Bitcoin Engineering and Security team states that some Coldcard firmware versions skip the hardware random number generator when generating keys.

The report states that the device's configuration allows it to bypass a hardware random source and instead generate keys using software. This process relies on non-confidential data such as chip serial numbers and clock registers. Because this information is not secret, attackers can use it to narrow down their guesses and potentially recover the wallet seed.

Block traced this change back to a code commit on March 1, 2021, and said the issue was subsequently incorporated into the 4.0.0 firmware released that month.

The affected area refers to Mk3 devices.

Coinkite has advised users to carefully check wallet seeds created on Mk3 devices using firmware version 4.0.1 or later. The company initially stated that Mk4, Q, and Mk5 models do not appear to be affected at present.

The report also mentioned that the risks are not limited to ordinary wallet seeds. Paper wallet private keys, seed split masks, device cloning keys, and Key Teleport transfer functions that use the same generation logic may also be affected.

Block stated that it has notified Coinkite of its findings, and the latter has confirmed receipt of the information. Both parties acknowledge that the current analysis is still in its preliminary stages, but Block believes that given the attack has already occurred, it is disclosing the findings before completing all exploitability testing.

Additional information:From a market perspective, this large-scale transfer has not yet had a significant impact on the price of Bitcoin. At the time the report was published, Bitcoin was still above $64,000 in early Asian trading.

Tip
$0
Like
0
Save
0
Views 971
HQYC reminds readers to view blockchain rationally, stay aware of risks, and beware of virtual token issuance and speculation. All content on this site represents market information or related viewpoints only and does not constitute any form of investment advice. If you find sensitive content, please click“Report”,and we will handle it promptly。
Submit
Comment 0
Hot
Latest
No comments yet. Be the first!
Related
Web3: Coldcard key vulnerability leads to the theft of approximately 594 bitcoins.
Coinkite claims that the Coldcard seed generation vulnerability has resulted in the theft of approximately 594 bitcoins, and attackers may have used AI to discover the problem.
Decrypt
·2026-07-31 17:25:06
855
Web3: The Thai Securities and Exchange Commission accuses Bitkub of concealing a $50 million theft.
The Thai Securities and Exchange Commission has accused Bitkub of concealing a 2021 cyberattack that resulted in approximately $50 million in losses. The case has been transferred to the police for investigation.
CoinDesk
·2026-07-27 21:41:55
538
Web3: Phishing emails impersonating Ledger updates lead to the theft of 400,000 XRP.
Phishing emails impersonating Ledger updates resulted in the theft of approximately 400,000 XRP from one holder.
Coinpedia
·2026-07-28 02:33:07
337
Web3: Samsung Wallet plans to add stablecoin functionality.
Samsung plans to add stablecoin support to Samsung Wallet, but has not yet disclosed the currency, timeline, or partners.
crypto.news
·2026-07-24 19:18:54
453
web3: BitGo adds 4 quantum risk controls to its Bitcoin wallet
BitGo has launched four quantum risk control features for institutional Bitcoin wallets, focusing on reducing public key exposure and optimizing UTXO management.
Cryptonews
·2026-07-30 15:35:10
193