An attacker exploited a flaw in Coldcard hardware wallets to steal roughly 594 bitcoin, worth about $38 million, from around 500 single-signature wallets on Friday, according to CoinDesk and Forbes reports.
The security vulnerability allowed the attacker to sweep funds from affected devices in under 30 minutes between 01:31 and 01:56 UTC.
Firmware Bug and Key Generation Risk
The exploit targeted predictable software-based key generation caused by a firmware bug introduced in March 2021.
Canadian firm Coinkite, the maker of Coldcard, issued a warning regarding specific hardware versions while advising users on key generation risks.
"Out of an abundance of caution, Coinkite is warning all users who generated a seed using a Mk3 on version 4.0.1 (March 2021) or any subsequent version that their funds may be at risk," Coinkite developers wrote in a blog post.
The company acknowledged that the internal bug went undetected prior to the exploitation, noting that newer hardware builds appear unimpacted based on initial findings.
"We were unaware of the bug until today," they added, advising users to "proceed calmly, verify every step," and move their funds to a new wallet.
Coinkite further emphasized that simply updating the software on an existing device does not secure previously generated wallet seeds.
"Updating the firmware does not repair a seed that was generated by affected firmware. A new seed must be generated and the funds migrated to the new wallet ...
When migrating to a new key, calm and care should be applied.
Rushing a wallet migration can create a more immediate risk than the issue you are trying to address."
Security researchers at Jack Dorsey's Block discovered that the bug bypassed the hardware randomness generator due to a faulty build setting in firmware version 4.0.0.
The flaw forced devices to fall back on nonsecret chip data, including serial numbers and clock registers, to generate seed phrases.
Block warned that transferring vulnerable seeds to secondary applications does not resolve the security exposure.
"If you exported a seed generated in a vulnerable Coldcard, moving it to another wallet, then that same insecure seed is still affected," security researchers with Jack Dorsey's Block wrote in a blog post.
Commentators and industry figures expressed concerns on social media over the implications of the exploit, including potential automated security threats.
"The exploit is out in the wild, public attention is on it, and everybody has access to frontier LLMs [large language models]," a pseudonymous onchain analyst and prominent crypto skeptic using the handle @Pledditor posted to X.
"I imagine there are dozens of hacking teams now researching how to exploit this. You are in a race against time."
Additional market observers warned that public exposure of the vulnerability could impact broader market sentiment and asset pricing.
"I have a very bad feeling AI was involved in this unfolding situation with Coldcard's being drained," X user Cobra, the pseudonymous co-owner and administrator of the prominent Bitcoin.
org website, posted to X, adding bitcoin could collapse under $60,000 as a result.
The administrator warned that wider news coverage might apply downward pressure on cryptocurrency values.
"This will bring us down to $58,000 when the media get a hold of it," Cobra posted.
Despite the attack, bitcoin remained above the $64,000 price mark in early Asian trading hours, showing minimal immediate market reaction.