⌂ Home News Coldcard Wallet Flaw Exploited to Steal $38 Million in Bitcoin

Coldcard Wallet Flaw Exploited to Steal $38 Million in Bitcoin

Coldcard Wallet Flaw Exploited to Steal $38 Million in Bitcoin
Anthropic AI models security testing
A A Text Size16px

An attacker exploited a flaw in Coldcard hardware wallets to steal roughly 594 bitcoin, worth about $38 million, from around 500 single-signature wallets on Friday, according to CoinDesk and Forbes reports.

The security vulnerability allowed the attacker to sweep funds from affected devices in under 30 minutes between 01:31 and 01:56 UTC.

>>> Emirates Flight EK225 Diverts to London After Medical Emergency

Firmware Bug and Key Generation Risk

The exploit targeted predictable software-based key generation caused by a firmware bug introduced in March 2021.

Canadian firm Coinkite, the maker of Coldcard, issued a warning regarding specific hardware versions while advising users on key generation risks.

"Out of an abundance of caution, Coinkite is warning all users who generated a seed using a Mk3 on version 4.0.1 (March 2021) or any subsequent version that their funds may be at risk," Coinkite developers wrote in a blog post.

The company acknowledged that the internal bug went undetected prior to the exploitation, noting that newer hardware builds appear unimpacted based on initial findings.

"We were unaware of the bug until today," they added, advising users to "proceed calmly, verify every step," and move their funds to a new wallet.

Coinkite further emphasized that simply updating the software on an existing device does not secure previously generated wallet seeds.

"Updating the firmware does not repair a seed that was generated by affected firmware. A new seed must be generated and the funds migrated to the new wallet ...

When migrating to a new key, calm and care should be applied.

A
Editors Team
Author: Angkasa Pura
📰 Latest Updates