Coldcard seed flaw tied to $100 million in Bitcoin theft

A long-undetected flaw in Coldcard's seed phrase generation process has been linked to roughly $100 million in Bitcoin theft, with Galaxy Research estimating 1,596 BTC was taken from about 7,300 addresses. The issue arose during a 2021 firmware overhaul, when a configuration error caused the hardware wallet maker's devices to use a more predictable software-based random number method instead of sufficient randomness from dedicated hardware, reducing the entropy (measure of randomness) used to create wallet seeds. Analysts said that made it feasible for attackers to narrow down possible seed combinations and recover private keys (secret codes controlling funds). Coldcard has released patched firmware, but said wallets created under the vulnerable firmware remain at risk unless users generate new seeds and move their BTC to fresh addresses.

The information on this website is generated using AI and we cannot guarantee its accuracy. Please use it as reference information only.