By Interestana AI Editorial — AI-drafted, human-overseen. How we report
Coldcard Bug Led to $100 Million in Hacked Crypto Funds

A critical security vulnerability within the firmware of Coldcard, a hardware cryptocurrency wallet, remained undetected for several years, ultimately contributing to an estimated $100 million in stolen digital assets. The bug, identified and disclosed by security researcher "0xB10C" on March 15, 2024, involved a flaw in the device's handling of the "PSBT" (Partially Signed Bitcoin Transaction) format. Specifically, the vulnerability allowed for the bypass of a crucial security verification step that is designed to ensure the integrity of transaction data before it is signed by the hardware wallet. This bypass meant that malicious actors could potentially alter transaction details, such as the recipient address or the amount, after the user had initiated the transaction and the Coldcard had begun the signing process, without the user being alerted to the change.
Coldcard, developed by Coinkite, is a popular hardware wallet among Bitcoin enthusiasts due to its focus on security and air-gapped operation, meaning it does not connect directly to the internet. The company's ethos emphasizes user control and verification, aligning with the crypto community's mantra of "don't trust, verify." However, this particular bug undermined that principle by allowing a critical verification step to be circumvented. The PSBT format is a standard used to facilitate the signing of Bitcoin transactions by multiple parties or devices, commonly employed in multisignature setups or when using hardware wallets. The vulnerability exploited a loophole where the device would proceed to sign a transaction even if its contents were tampered with post-initialization, effectively deceiving the user into signing a transaction that was not what they intended.
While the exact timeline of when the bug was introduced into the Coldcard firmware is not precisely detailed, "0xB10C" indicated that it had been present for a significant period, potentially years. The disclosure came after the researcher independently discovered the flaw and subsequently reported it to Coinkite. The estimated $100 million figure represents the total value of cryptocurrency that has been confirmed or is strongly suspected to have been lost due to exploits leveraging this vulnerability. This incident highlights the persistent challenges in securing digital assets, even with specialized hardware designed for maximum security. The reliance on complex software, such as firmware, introduces inherent risks, and the long-term undetected nature of this bug underscores the difficulty in comprehensive security auditing for such devices.
In response to the disclosure, Coinkite acknowledged the vulnerability and stated that they were working on a firmware update to address the issue. The company also advised users to exercise extreme caution when signing transactions and to meticulously verify all transaction details on their device's display before confirming. The incident serves as a stark reminder for all cryptocurrency users, regardless of the security measures they employ, to remain vigilant and to perform thorough due diligence when interacting with their digital assets. The long-term presence of the bug and the substantial financial losses incurred underscore the importance of continuous security research and proactive vulnerability management within the cryptocurrency hardware industry.
Original source — read the full reporting at the publisher:
Read on CoinDeskGet the weekly AI digest
AI news + new model releases, weekly. Drafted by our agents, reviewed by humans.