Coldcard Security Flaw Leads to Massive Bitcoin Theft
A firmware bug in Coldcard hardware wallets has allowed attackers to steal nearly 600 Bitcoin by predicting private keys.
BTCcoinbeat.news
BTC/USD live chart
LIVEA critical firmware error in Coldcard hardware wallets has created a security hole that lets attackers guess private keys. This flaw has already resulted in the loss of 594.48 Bitcoin, currently valued at roughly 38.3 million dollars. Researchers at Block and Coinkite discovered that the device's random number generator was disabled, forcing the wallet to create keys based on predictable data like serial numbers and internal clocks.
The issue affects devices that received firmware updates since 2021. Because the seed phrases are generated using patterns rather than true randomness, attackers can test possible combinations to reconstruct a user's private key. This does not require physical access to the device. Any wallet where the public key or address is visible online is a potential target for this exploit.
Coinkite advises that firmware updates alone cannot fix a compromised seed phrase. If you generated a seed on an affected device, you should generate a brand new seed on updated hardware and move your funds immediately. Using a strong passphrase in addition to your seed phrase provides an extra layer of protection, as it significantly complicates the ability for attackers to guess the correct key.
While the company continues to investigate the full extent of the issue, owners of older Coldcard models should act with caution. Assume any seed generated before the latest security patches could be compromised. Moving assets to a fresh, secure wallet remains the safest path for all users concerned about their holdings.
Prices update live from CoinMarketCap. Market data, not financial advice.
Market sentiment
Be the first to react
▍Comments (0)
No comments yet. Start the conversation!



