Major bitcoin wallet flaw drains 594 BTC in 25-minute sweep
A hardware wallet randomness bug turned “impossible to guess” seeds into guessable ones, and $38 million is already gone.
Make preferred on
Share this article
Summary
- An attacker exploited a flaw in how some Coldcard hardware wallets generated keys to steal roughly 594 bitcoin, worth about $38 million, from around 500 single-signature wallets in under 30 minutes.
- The vulnerability, introduced in Coldcard firmware 4.0.0 in March 2021, caused devices to skip their hardware randomness generator and fall back to predictable software-based key generation seeded by nonsecret chip data.
- Coinkite has warned users who created seeds on Mk3 devices running firmware 4.0.1 or later, while stressing that Mk4, Q and Mk5 appear unaffected so far, and the theft has had little visible impact on bitcoin’s market price.

