- Attackers drained approximately 600 Bitcoin ($40 million) from hundreds of Coldcard hardware wallets due to a firmware bug that caused predictable key generation.
- Coinkite urges all Mk3 users on firmware version 4.0.1 or later to generate new seeds and migrate funds immediately.
- Security researchers from Block warn that seeds generated on vulnerable Coldcards remain insecure even if exported to other wallets.
- Fears of further Bitcoin Price decline below $58,000 have emerged as the media reports the attack, with some suggesting AI tools may have been used.
Last night, panic swept the crypto community when reports emerged that nearly 600 bitcoin—worth approximately $40 million—was stolen from hundreds of Coldcard hardware wallets their owners believed were secure. Attackers exploited a firmware bug that caused the wallets to use predictable software-based key generation seeded by chip data rather than a sophisticated randomness generator.
The vulnerability affected Coldcard Mk3 devices running firmware version 4.0.1 (March 2021) or any subsequent version. Coinkite, the Canada-based creator of Coldcard, warned users in a blog post: “Out of an abundance of caution, Coinkite is warning all users who generated a seed using a Mk3 on version 4.0.1 or any subsequent version that their funds may be at risk.” They added that updating firmware does not repair an already compromised seed and advised calm migration to a new wallet.
Consequently, the threat extends beyond Coldcard itself. Security researchers with Block (Jack Dorsey’s company) wrote that “if you exported a seed generated in a vulnerable Coldcard, moving it to another wallet, then that same insecure seed is still affected.” Meanwhile, the bitcoin price has dropped since the attack was discovered, though it remains above the key $60,000 support level.
Fears are now swirling that media coverage could drive the price lower, potentially sending it crashing under the $58,000 level seen at the end of June. A pseudonymous analyst posting to X warned: “The exploit is out in the wild, public attention is on it, and everybody has access to frontier LLMs. I imagine there are dozens of Hacking teams now researching how to exploit this.” Another prominent X user, the co-owner of Bitcoin.org, added: “I have a very bad feeling AI was involved in this unfolding situation.”
✅ Follow BITNEWSBOT on Telegram, Facebook, LinkedIn, X.com, and Google News for instant updates.
