Interestana
Home/News/Coldcard Wallet Flaw Linked to $70M Bitcoin Theft
The Hacker News3 min read

By Interestana AI Editorial — AI-drafted, human-overseen. How we report

Coldcard Wallet Flaw Linked to $70M Bitcoin Theft

Coldcard Wallet Flaw Linked to $70M Bitcoin Theft

A sophisticated attack on July 30 successfully drained 1,196 Bitcoin addresses, resulting in the theft of 1,082.65 Bitcoin, valued at approximately $70.2 million at the time of the incident. The rapid nature of the theft, completed within 41 minutes, indicated a highly efficient exploitation of a vulnerability. Research conducted by Galaxy Research has mapped the extensive sweep of these Bitcoin addresses and has linked the attack to a specific firmware flaw present in Coldcard, a hardware wallet designed exclusively for Bitcoin. This vulnerability is believed to have been introduced through a firmware integration error that occurred in March 2021. The error reportedly caused the seed generation process to be routed to a deterministic software pseudorandom number generator (PRNG). A deterministic PRNG generates a sequence of numbers that is predictable if the initial state, or seed, is known. In the context of cryptocurrency wallets, the seed phrase is a critical component used to generate private keys, which control access to Bitcoin holdings. If the seed generation process is compromised and predictable, an attacker could potentially derive the private keys associated with multiple wallets, allowing them to steal the funds. The Coldcard hardware wallet is manufactured by Coinkite, a Canadian firm specializing in Bitcoin-related hardware security solutions. Hardware wallets are designed to store private keys offline, providing a significant security advantage over software wallets that store keys on internet-connected devices. However, vulnerabilities in the firmware or hardware itself can undermine these security measures. The precise technical details of how the attacker exploited the deterministic PRNG to compromise the seed generation and subsequently access the funds are still under investigation. This incident highlights the ongoing challenges in securing digital assets, even with specialized hardware solutions, and underscores the importance of rigorous security audits and rapid patching of firmware vulnerabilities. The theft represents one of the largest single-incident Bitcoin thefts attributed to a hardware wallet vulnerability, emphasizing the significant financial risks associated with even minor security flaws in critical infrastructure. Galaxy Research's detailed mapping of the transaction flows and their attribution to the Coldcard flaw provide a crucial piece of evidence in understanding the mechanics of this high-value exploit. The incident is expected to prompt further scrutiny of hardware wallet security practices and potentially lead to enhanced security protocols from manufacturers like Coinkite.

Original source — read the full reporting at the publisher:

Read on The Hacker News

Get the weekly AI digest

AI news + new model releases, weekly. Drafted by our agents, reviewed by humans.

Read next