← Back

Faulty RNG in Coldcard crypto wallets lets hackers drain $88.6M in bitcoin

Original version ·

Nothing says ultimate self-custody quite like keeping digital wealth on a battle-tested iron vault, only for a software typo to hand the master keys right over to an automated bot script.

Security firm Galaxy Research spotted the first wave of automated drains when 1,083 bitcoins vanished from 1,196 wallets in just 41 minutes. The attacker set a rigid transaction fee of 30 satoshis per vByte—roughly 30 to 75 times higher than normal network rates—making it clear that a relentless script was cleaning house while human owners were likely grabbing coffee.

Subsequent waves pushed the total haul to 1,367 bitcoins worth $88.6 million across 4,585 compromised wallets. Intelligence from Chainalysis revealed that the hackers spent weeks quietly index-matching targets offline, prioritising high-value wallets first to snatch $30 million in the first ten minutes alone.

Engineers at payments firm Block dissected the firmware and found that Coinkite's hardware random number generator failed silently due to a code integration bug. Instead of throwing an error, Coldcard devices silently defaulted to a predictable software pseudorandom generator built on basic chip IDs and system timestamps.

Because the fallback math was completely deterministic, attackers were able to pre-calculate seed phrases on their laptops, derive matching addresses, and monitor the public Bitcoin ledger for a match. Affected hardware includes legacy Coldcard Mk2 and Mk3 units running firmware 4.0.1 through 4.1.9, alongside unpatched Mk4, Mk5, and Q series devices.

While Coinkite released patched firmware, updating the software code cannot fix an already compromised seed phrase. Holders must flash the update, generate a fresh seed from scratch, and manually transfer their remaining funds.

Crypto maximalists spent a decade insisting that paper pieces and offline metal plates were impenetrable bastions against systemic collapse, only for a lazy fallback loop to turn physical security into a public charity drive for hackers.

Source: Coinkite

Comments

This is where the magic happens: AI reads your discussion and rewrites the article based on the most interesting comments. Each strong comment adds points to the meter below. Once the meter is full, the article updates live — no page reload needed.

0/24
  1. No comments yet.