Coldcard Wallet Flaw Exploited by 15+ Attackers for $100M Bitcoin Theft

BTC0.31%

Galaxy Digital head of research Alex Thorn reported that at least 15 different attackers exploited a Coldcard hardware wallet vulnerability, with new victim reports revealing previously unidentified thefts. The exploitation resulted from a firmware integration error that caused affected wallets to rely on a deterministic pseudorandom number generator instead of a hardware-based random-number generator. Galaxy Research estimates approximately $100 million in Bitcoin was stolen across three confirmed attack waves, with a suspected fourth wave potentially increasing total losses to around $130 million.

Thorn stated the reports allowed Galaxy researchers to connect additional Bitcoin addresses to the incident. In one case, a victim who lost less than 1 Bitcoin helped researchers identify an attacker that siphoned 12 BTC from 126 addresses. Unlike a centralized exchange breach, the thefts involved funds moving from numerous independently controlled wallets to multiple attacker addresses. Researchers may be unable to identify some thefts unless victims disclose their wallet addresses and transactions. The 15 attacker clusters do not necessarily represent 15 known individuals, as some addresses could be controlled by the same person or group, while other attackers may remain undiscovered.

Coldcard Bug Weakened Wallet Seed Generation

The vulnerability affected the process used by some Coldcard devices to generate recovery phrases. A firmware integration error reportedly caused affected wallets to rely on a deterministic pseudorandom number generator instead of the intended hardware-based random-number generator. This reduced the effective randomness protecting some private keys and made it more practical for attackers to search for valid seed phrases.

Castle Labs co-founder Francesco stated affected Coldcard wallets may have generated private keys with roughly 40 bits of entropy. A standard 12-word recovery phrase normally provides 128 bits. This did not mean attackers could directly extract keys from an air-gapped device. Instead, they could recreate possible recovery phrases and monitor the associated Bitcoin addresses for funds.

Users with potentially affected wallets have been advised to update their firmware, generate an entirely new seed phrase and transfer their Bitcoin to addresses controlled by the new wallet. Merely importing an affected recovery phrase into another device does not resolve the underlying weakness.

AI Security Testing Debate Emerges Following Exploit

The incident prompted debate over whether AI-assisted security testing could have discovered the flaw sooner. Dragonfly managing partner Haseeb Qureshi argued that approximately "$2 of AI hardening" might have prevented the losses. He referenced experiments claiming that AI models rediscovered the vulnerability within minutes, including a test in which the open-source GLM 5.2 model reportedly found it in about 20 minutes without web access.

Critics questioned whether the experiments prove that AI could have found the vulnerability before it became public. Tokenomist data lead Tatsapat Saerejittima stated that some tests were conducted after disclosure and lacked blind testing, documented methodologies and assessments of false positives.

FAQ

How many attackers exploited the Coldcard wallet vulnerability?

Galaxy Digital research identified at least 15 different attacker clusters that exploited the Coldcard hardware wallet vulnerability. These 15 clusters do not necessarily represent 15 known individuals, as some addresses could be controlled by the same person or group.

What caused the Coldcard wallet security weakness?

A firmware integration error caused affected Coldcard wallets to rely on a deterministic pseudorandom number generator instead of the intended hardware-based random-number generator. This reduced the effective randomness protecting private keys, with affected wallets generating keys with roughly 40 bits of entropy compared to the standard 128 bits provided by a normal 12-word recovery phrase.

How much Bitcoin was stolen in the Coldcard exploit?

Galaxy Research estimates approximately $100 million in Bitcoin was stolen across three confirmed attack waves. Researchers identified a suspected fourth wave that could increase total losses to around $130 million.

Disclaimer: The information on this page may come from third-party sources and is for reference only. It does not represent the views or opinions of Gate and does not constitute any financial, investment, or legal advice. Virtual asset trading involves high risk. Please do not rely solely on the information on this page when making decisions. For details, see the Disclaimer.
Comment
0/400
No comments