HomeSecurityColdcard bug: Critical firmware issue linked to 70 million Bitcoin theft....

Coldcard bug: Critical firmware issue linked to $70 million Bitcoin theft

A Coldcard bug in the way it generates seed phrases is linked to a massive Bitcoin outflow worth approximately $70.2 million. The disclosure involves firmware that used a predictable random number generator instead of the intended hardware source.

Coldcard error on hardware wallet

According to analysis by The Hacker News, on July 30, 1,082.65 BTC was moved from 1,196 addresses in just 41 minutes. Galaxy Research mapped the transaction and linked it to the vulnerability, without publicly attributing the action to a specific perpetrator.

See also: Ill Bloom: Vulnerability allowed $3.1 million to be stolen from crypto wallets

How the Coldcard error occurred

The root of the problem lies in the integration of code dating back to 2021. As Block’s technical analysis, the control library did not properly evaluate a compilation flag. This allowed the device to fall back on MicroPython’s deterministic Yasmarang generator, rather than using the STM32 microcontroller’s random source.

On Mk2 and Mk3 with firmware 4.0.0 to 4.1.9, the process could be made predictable when the attacker knew or limited the unique device identifier, timer state, and generator call history. On Mk4, Mk5, and Q, some entropy was added from the secure element, but rebooting limited the secure contribution to 32 bits.

This does not involve remote access to the wallet itself or the disclosure of the PIN. It concerns the stage before its use: if the initial recovery phrase was generated with insufficient randomness, the security of subsequent signatures depends on a smaller set of possible keys. This explains why updating the software alone is not enough.

Predictable Coldcard seed phrase generation

The practical consequence is that an attacker can generate candidate recovery phrases off-device and check the corresponding addresses on the public blockchain. Block emphasizes that research is ongoing and that the method has not been proven with a full reconstruction of every affected phrase. The pattern of large transfers, however, was enough to raise alarm bells.

Which users should take action?

The official Coinkite update page lists patched versions 4.2.0 for Mk3, 5.6.0 for Mk4 and Mk5, and 1.5.0Q for Q. Installing the update is required, but it does not fix the seed phrase created with the vulnerable firmware. Holders must generate a new seed on the patched version and transfer funds.

Coinkite estimates the effective entropy at around 40 bits for Mk3 and up to 72 bits for Mk4, Mk5, and Q, instead of the 128 bits expected from a 12-word seed. Those who used at least 50 fair, independent, and private dice rolls when generating the seed are not considered exposed to this specific flaw alone, according to the company's technical background.

See also: Starland RAT: Russian-speaking group steals crypto wallets

Transferring funds after a wallet vulnerability

Firmware is not enough for Coldcard error

Restoring the old seed to another device carries the vulnerability with it. Therefore, the safe procedure is to generate a new seed, carefully verify the wallet fingerprint, and do a small test transaction before transferring the full balance. The strong, unique BIP-39 phrase creates a separate wallet, but is not a substitute for migration.

The Coldcard bug requires checking the creation time, not just the current version. Users should note the model, the version installed when the phrase was created, and whether private dice rolls were used. The new phrase should be kept offline, checked after reboots, and stored in more than one secure physical location. Every transfer requires verification of the address on the device itself, not just on the computer screen.

In multi-signature wallets, the protection only applies when the required threshold is not based solely on affected devices. Coinkite also notes that TAPSIGNER, OPENDIME, and SATSCARD use different code bases. The incident is a reminder that even an offline device needs verifiable randomness generation and prompt revocation management.

See also: OkoBot: Framework with payloads for cryptocurrency theft

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

New secure seed on Coldcard

The SecNews technical team recommends that users immediately check the firmware version and seed creation history, follow only Coinkite's instructions, and avoid hasty transfers without a second address check.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS