Hardware Wallet Security Flaw

COLDCARD Vulnerability Linked to $88 Million Bitcoin Theft?

COLDCARD vulnerability, Bitcoin theft, COLDCARD vulnerability linked to Bitcoin theft, COLDCARD hardware wallet security vulnerability, Bitcoin theft caused by weak random number generation, COLDCARD, Bitcoin
Facebook
X
LinkedIn
Reddit
WhatsApp

A vulnerability in the firmware of the COLDCARD hardware wallet is suspected to be behind the theft of approximately $88.6 million worth of Bitcoin.

According to digital asset research firm Galaxy Research, attackers drained around 1,083 Bitcoin worth $70.2 million at the time from 1,196 addresses in just 41 minutes on July 30. The attack took place roughly 30 hours before manufacturer Coinkite publicly disclosed the vulnerability. All transactions used an identical, hard-coded fee of 30 satoshis per virtual byte, a 30 to 75 times premium over the market average at the time. None of the transactions included a change output, which Galaxy Research considers evidence of an automated tool systematically exploiting keys that were already in the attackers’ possession.

Ad

On August 1 and 2, Galaxy Research identified two additional waves of attacks, including a third wave that drained another 207.7 Bitcoin. The company estimates the total observed losses so far at approximately 1,367 Bitcoin worth around $88.6 million, spread across 4,585 addresses. Blockchain analytics firm Chainalysis also found that the attackers prioritized the highest-value wallets, draining around $30 million within the first 10 minutes alone. This suggests that the targeted addresses had been identified in advance. The stolen Bitcoin had remained untouched for an average of around 3.18 years before the attacks. Based on current knowledge, the funds have remained entirely in addresses controlled by the attackers.

Flaw in Random Number Generation

After the first thefts were discovered, security teams at Block, together with other researchers, analyzed the device firmware and reported their findings to Coinkite on July 30. The root cause was reportedly an integration error dating back to a March 2021 firmware update. As a result, the device’s random number generation function did not use the chip’s built-in hardware random number generator. Instead, it relied on a deterministic software fallback provided by MicroPython.

The fallback used the microcontroller’s identifier and device timing measurements. According to Block, these values are not cryptographically secure and may potentially be observable or reconstructable. This could allow attackers to precompute possible wallet seeds offline, derive the corresponding Bitcoin addresses and compare them against addresses visible on the blockchain to identify matches.

Ad

Affected Versions and Recommended Migration

According to a security advisory from Coinkite, seeds generated on Mk2 and Mk3 devices running firmware versions 4.0.1 through 4.1.9 are affected. The same applies to Mk4 and Mk5 devices running versions earlier than 5.6.0 or Edge version 6.6.0X, as well as Q devices running versions earlier than 1.5.0Q or Edge version 6.6.0QX.

While updated firmware fixes the underlying issue for newly generated seeds, it does not retroactively secure seeds that were generated previously. Coinkite advises affected users to verify their existing backup, install the corrected firmware, generate a new seed and record it securely, verify the new wallet address on the device, conduct a small test transaction and only then transfer the remaining funds. The old backup should be retained until the migration has been fully completed and confirmed.

According to Coinkite, seeds supplemented with at least 50 fair, independent dice rolls performed privately are not considered vulnerable to this specific flaw alone. A strong, unique BIP-39 passphrase also makes exploitation more difficult, but does not replace the recommended migration process.

Coinkite’s Tapsigner, Opendime and Satscard products are not affected, according to the company, as they are based on a different codebase. Coinkite also said that devices with the vulnerable firmware that had already been prepared for shipment but had not yet been delivered were destroyed. Devices that had already been shipped were covered by an email notification about the security advisory.

(ll)

Ad

Artikel zu diesem Thema

Weitere Artikel