Coldcard flaw exposed 1,596 Bitcoin worth over $100 million, Galaxy says

A flaw in Coldcard’s seed-generation process helped attackers steal 1,596 bitcoin worth over $100 million from about 7,300 addresses, according to Galaxy Research, in a breach that also cost Toronto entrepreneur Jonathan Goodman 18.25 bitcoin worth just over $1.17 million on July 29. Galaxy research head Alex Thorn said on Aug. 4 that at least 15 different attackers were exploiting the weakness, which did not require physical access to devices. The issue was not that Coldcard hardware wallets went online, but that some wallets generated recovery seeds with far less randomness than intended, making them more feasible to reproduce or narrow down. Block’s Bitcoin engineering and security team said a configuration error caused the device to use a weaker software random-number generator instead of a dedicated hardware source. Coinkite said affected Mk2 and Mk3 devices received no secure randomness through that process, while Mk4, Q and Mk5 devices retained only a small share, producing seeds with 72 bits of randomness rather than the intended 128. Coinkite has released fixed firmware, but users with seeds created under vulnerable software must generate a new seed and move funds, because the update does not secure already-created wallets. The episode underscores that self-custody (holding your own crypto keys) still depends on wallet makers to generate those keys safely.

The information on this website is generated using AI and we cannot guarantee its accuracy. Please use it as reference information only.