- Coinkite Inc. notified users of its Coldcard devices that a security flaw in the keys protecting their cryptocurrency had compromised some wallets.
- Reports on Friday placed losses at around $38 million.
- Over the weekend, losses climbed as attackers continued draining wallets.
- By Monday, roughly 1,367 Bitcoin worth about $86 million had been drained from more than 4,500 wallets, according to Galaxy Research.
- Coinkite says fixed firmware is now available for every affected Coldcard model and release track.
- Coldcard is a brand of hardware device that allows users to secure their bitcoin in so-called cold wallets, which are considered one of the safest places to store cryptocurrency.
- A flaw in the software of the Coldcard devices meant that the generated seed phrase was predictable, according to a report from Block Inc.'s engineering team.
- True randomness is a critical component of cryptographic security, but Coldcard wallets had a fallback mechanism that resulted in keys generated using deterministic values such as the device serial numbers.
- Hackers have been able to systematically recalculate and drain user wallets due to this flaw.
Hackers have discovered a significant software vulnerability in Coldcard wallets, a popular choice for securely storing Bitcoin. This flaw has allowed them to siphon off approximately 1,367 Bitcoin, valued at $86 million, from over 4,500 wallets as of Monday, according to Galaxy Research.469
Coinkite Inc., the Canadian company behind Coldcard, alerted users late last week about the compromised security keys protecting their cryptocurrency. The issue stems from a predictable seed phrase generation process, which is critical for wallet access. A report from Block Inc. revealed that the random-number generator used by Coinkite was flawed, relying on deterministic values like device serial numbers instead of true randomness.1578
“It exposes the fallacy of your crypto being offline,” stated Aneirin Flynn, CEO of cybersecurity firm Failsafe. “The device is just responsible for generating your passwords, and if the underlying math is broken then your passwords can be reverse-engineered.” Victim Jonathan Goodman recounted his experience, stating, “The moment it loaded I knew I was screwed because I saw red lines for withdrawals.” He lost access to all three of his wallets within minutes.

Initially, reports estimated losses at around $38 million, but this figure escalated rapidly over the weekend. Coinkite has since confirmed that funds controlled by seeds generated on the affected firmware are at risk and has released fixed firmware for all impacted models.2
Despite a decrease in total crypto thefts this year, with losses reaching $972 million in the first half, the number of hacks has surged to 207, marking the highest recorded in any six-month period.
“By Monday, roughly 1,367 Bitcoin worth about $86 million had been drained from more than 4,500 wallets, according to Galaxy Research. The flaw stemmed from a fallback in Coldcard’s random-number generator that made seed phrases predictable, prompting one victim to describe all three of his wallets being drained in minutes.”
