- At least 15 attackers have drained over $130 million from 7,300+ Coldcard wallets exploiting a firmware flaw that generated weak private keys, Galaxy Research reports.
- The vulnerability, caused by a pseudo-random number generator in MicroPython, reduced seed entropy to roughly 40 bits on Mk2 and Mk3 models, making brute-force attacks feasible.
- Coinkite has shipped hotfixes but warns that updating firmware does not repair seeds already generated, and “the threat is still active.”
Over 15 separate attackers have drained more than $130 million from at least 7,300 Coldcard hardware wallets, Galaxy Research concluded Tuesday, as exploitation of a newly discovered firmware flaw continues. The number of thieves appears to be growing daily, with Galaxy identifying a 15th attacker overnight after a victim reported losing less than one BTC.
The vulnerability stems from Coldcard’s firmware routing seed generation into MicroPython’s software fallback, a pseudo-random number generator instead of a true random generator. Coinkite, the manufacturer, estimates that Mk2 and Mk3 models produced seeds with only about 40 bits of entropy, far below the 128-bit target.
Consequently, any Hacker with sufficient knowledge and computational power can scan Bitcoin’s blockchain for vulnerable wallets and brute-force guess the private keys. Galaxy Research has heard from 73 victims as of Monday, and many long-term holders may not yet realize their losses.
Coinkite co-founder Rodolfo Novak wrote on July 31, “We take full accountability for the firmware bug and we offer our sincere apologies to those affected.” The company has since shipped hotfixes for every affected model but warned again today, “The threat is still active.”
Affected owners must move their BTC to new wallets, as updating the firmware does not repair a seed generated by flawed firmware. Interestingly, Galaxy reports that 90% of stolen coins have not moved, and none of the coins from the first three attack waves have been spent.
✅ Follow BITNEWSBOT on Telegram, Facebook, LinkedIn, X.com, and Google News for instant updates.
