The Coldcard Exploit: A Deep Dive Into One Of The Most Significant Hacks In Recent Memory
0
0

Coldcard is a Bitcoin-only hardware wallet created by Coinkite, a Toronto-based company specializing in ultra-secure self-custody hardware. The hardware wallet is marketed as a highly secure cold storage option for long-term Bitcoin users and has received plaudits from users and experts alike. However, the Coldcard exploit could change that perspective and have far-reaching implications for “self-custody,” a hill many in crypto choose to die on.
The Coldcard Exploit Timeline
Let’s get into the nitty-gritty of the exploit. On July 30, individual Bitcoin holders using Coldcard noticed that their wallets were inexplicably drained. Among them was author Jonathan Goodman, who lost $1.6 million in BTC to the exploit. Goodman’s post about the hack on X was possibly the first time the hack was discussed in the public domain. Meanwhile, blockchain intelligence firm Galaxy Research detected suspicious transaction waves in a 41-minute window, hours before Coinkite issued its first advisory regarding the exploit. Unlike most exploits, the Coldcard exploit unfolded in waves, with the number of affected wallets rising almost daily.
The vulnerability impacted several models, including the Mk2, Mk3, Mk4, Mk5, and Q. However, Coinkite products built on separate codebases, including Tapsigner, Opendime, and Satscard, were unaffected.
The first wave was detected on July 30, when a hacker or hackers began targeting Bitcoin held in Coldcard hardware wallets. The hackers drained 500 wallets in a 25-minute window during the first wave, siphoning around 594 BTC, worth around $38 million, to a new address. The numbers are staggering for such a small window, but this was just a prelude to what was to come. The first wave lasted 41 minutes and affected 1,196 wallets. As more data poured in, Galaxy Research pegged the first wave figures at 1,082.65 BTC stolen from 1,196 wallets, around 0.9 BTC from each wallet.
Galaxy Research detected two subsequent waves on July 31 and August 1, respectively. The hackers stole around 76 BTC from 1,477 wallets during the second sweep and 208 BTC from 1,912 wallets during the third sweep. A suspected fourth wave was detected on August 4, with researchers identifying an additional 600 wallets. Early estimates put losses at over $130 million, a figure that could increase as hackers continue targeting vulnerable addresses.
| Wave | Date | Wallets Affected | BTC Stolen |
| 1 | July 30 | 1,196 | 1,082.65 BTC |
| 2 | July 31 | Roughly 1,477 | 76 BTC |
| 3 | August 1 | 1,912 | 208 BTC |
| 4 (Possibly Ongoing) | Detected by August 4 | Over 600 | Figure Not Publicly Available |
A highly unusual aspect is the nature of the exploit. The BTC wasn’t stolen through an elaborate social engineering scheme or the usual phishing or exchange attacks that we usually see. It wasn’t even a supply chain compromise like the one that hit Ledger in 2023. This was a bug that sat undetected for five years, until someone, somehow, discovered it and used it to blindside Coldcard wallet users.
How Does The Coldcard Number Generator Work
Coldcard wallets generate their own randomness every time a user creates a new seed. The randomness underpins the security the wallets are known for. Any compromise to this randomness would prove disastrous, as the ongoing exploit has proved. These wallets are designed to generate and store private keys offline and are never directly connected to the internet. Instead, they communicate with the blockchain using an air-gapped environment through QR codes and MicroSD cards.
The Code That Started It All
At the heart of the exploit sits an innocuous firmware update pushed by Coldcard in March 2021. Firmware version 4.0.1 migrated Coldcard’s cryptography to libsecp256k1, the library underpinning Bitcoin Core, a sound decision by every definition of the word. However, this inadvertently moved seed generation to MicroPython’s Yasmarang PRNG, used on devices with no randomness chips.
You may be wondering why.
According to Block’s security and engineering team, the 2021 update changed how the firmware called its cryptographic library during the seed generation phase. The library misread a production build configuration flag that checks whether the hardware random number generator (RNG) was available. This event went unnoticed, and the firmware began generating “deterministic, pseudorandom seed phrases from a significantly smaller entropy pool without adding fresh entropy.”
Let me explain the preceding sentence. A hardware wallet typically uses two components: a physical randomness source embedded in the chip (TRNG) and an algorithm that uses true randomness from the TRNG to generate seed phrases (CSPRNG). Coldcard wallets use a hardware-based true random number generator built directly into its microchip. Additionally, users can add physical dice rolls to increase randomness.
When Coinkite pushed the 2021 update, the firmware reverted to a backup PRNG without alerting the user. The PRNG relied on the wallet’s UID instead of fresh entropy, making the output predictable. Here’s where the vulnerability comes in. If an attacker can determine a device’s possible UID, they could narrow down the seed phrases generated by the wallet.
So what effect did this have?
Seed phrases generated using firmware 4.0.1 looked like a standard 12- or 24-word phrase. However, the randomness of the underlying numbers was compromised, making them significantly weaker. A 12-word BIP-39 seed typically carries 128 bits of entropy. Let me put this unremarkable figure into perspective using a simple analogy. 128 bits of entropy effectively gives ~3.4 × 10³⁸ possible seeds. The age of the universe is 13.8 billion years. If a hacker tried to brute-force 128 bits of entropy at a trillion guesses per second, it would take them 800 million times the age of the universe to run through all possible combinations.
Entropy fell to 72 bits on Mk4, Mk5, and Coldcard Q devices, reducing the possible seeds to ~4.7 × 10²¹. This is well below the 128-bit threshold and exploitable by determined hackers with time and resources. It fell even lower (40 bits) on Mk2 and Mk3 devices, well within the reach of an attacker with even modest resources.
Now, you may read this and think an upgrade could fix the vulnerability. Not exactly. A firmware update fixes the problem for seeds generated after the vulnerability was patched. However, seeds generated using firmware 4.0.1 remain vulnerable. Coinkite has recommended that all users who created seed phrases using the compromised firmware generate a new seed phrase and move their funds to a new wallet.
Details And On-Chain Analysis
Galaxy Research highlighted differences in transaction construction across the attack waves, suggesting multiple threat actors instead of a single entity. A TechCrunch report cited other blockchain monitoring firms to confirm Galaxy Research’s observation, stating that Coldcard wallets were targeted by at least a dozen hackers.
Here is a breakdown of the attack waves that targeted Coldcard. However, these figures could change as analysts believe the exploit is ongoing and details of more affected wallets could emerge over time.
- Galaxy Research flagged suspicious transactions detected on July 30, identifying around 594 BTC drained from 500 single-signature wallets. The first wave lasted for 41 minutes, targeting 1,196 wallets and draining 1,082.65 BTC.
- The second wave followed the same pattern, with hackers draining 76 BTC from 1,477 wallets, taking the total to 1,158.66 BTC (~$75.1 million) from 2,673 addresses.
- The third wave targeted 1,912 wallets, draining 208 BTC and taking the total to 1,367 BTC (~$88–89 million) across over 4,500 addresses.
- The fourth wave could still be ongoing, with TRM Labs updating the figures to 1,816 BTC from over 5,200 addresses. These numbers could change as more reports come to light.
TRM Labs tracked the stolen BTC to a pool of addresses linked to the attackers. Surprisingly, the attackers have made very little attempt to move, launder, or mix the funds so far. This is likely because the attackers want to target as many vulnerable wallets as possible before worrying about laundering or mixing the stolen funds. A single deposit of 64.9 BTC on Wasabi and 200 ETH on Tornado Cash are the only laundering activity tracked so far.
This is probably why the exploit has not been attributed to groups like North Korea’s Lazarus that launder stolen funds within hours. Funnily enough, the hackers themselves are being inundated with spam messages, with one message offering to launder the stolen funds for a nominal fee.
Coinkite’s Response And Advisory
Coinkite issued several advisories as the scope of the exploit became clearer. The Coldcard manufacturer published a security advisory following the first wave. The initial advisory covered Mk3 devices and firmware 4.0.1 and 4.1.9. Coinkite released an updated advisory and firmware for Mk4/Mk5 (version 5.6.0 or later) and Coldcard Q (version 1.5.0Q or later). The advisory was updated again on August 1, confirming that the exploit had also impacted Mk2 devices. The latest advisory also narrowed the firmware impacted by the exploit and released a fixed firmware update for Mk2/Mk3 (version 4.2.0).
The update also officially recognized that seed phrases generated with at least 50 manual dice rolls contained enough randomness and were not at risk.
Coinkite has stressed that simply updating the firmware will not fix wallets that have already generated a seed. It advised users who generated a seed between March 2021 and the latest firmware update to treat their seed as compromised and move their funds to a new wallet or generate a new seed on a patched firmware.
Why Was The Coldcard Vulnerability Undetected For So Long
One of the biggest talking points of this entire episode is why nobody detected the bug, which was shipped in a firmware update in March 2021. One detail to remember is that Coldcard’s firmware is open source and publicly available. Coinkite speculated in one of its advisories that the bug may have been discovered during an AI-assisted review of the code. However, this theory is unconfirmed as of now.
The exploit adds to the ongoing conversation about hackers using AI systems to find and exploit vulnerabilities in already-reviewed code. Separately, several AI labs, including OpenAI, Anthropic, and Meta, have revealed that their models access real systems during testing. These incidents occurred due to misconfigured environments allowing the models to gain internet access, or because the AI models exploited vulnerabilities during certain tests.
Some recent examples include:
- One of OpenAI’s internal models accessed Hugging Face production infrastructure by breaking out of a test environment and exploiting a zero-day vulnerability.
- According to one report in ALMCorp, an Anthropic audit revealed some Claude models, including Opus 4.7 and Mythos 5, accessed the internet and gained unauthorized access to systems of three organizations.
- Meta’s Muse Spark AI model accessed an external company’s systems and altered internal data.
What Are The Implications For Bitcoin Self Custody
The Coldcard exploit could potentially change Bitcoin custody forever, raise questions about mass adoption, and highlight the complexities of self-custody. First, none of the affected users did anything wrong. They did not fall victim to a social engineering scam or click on a malicious link.
The incident has cast doubt on self-custody, a concept the Bitcoin and broader crypto community swears by. The exploit also reinforces the argument many have made that self-custody does not eliminate risk, it only relocates it. Some, including Taproot developer Udi Wertheimer, have argued that the community cannot assume that Bitcoin stored in cold wallets indefinitely is safe and users must remain vigilant about emerging threats.
The threat landscape has evolved as well. According to Blockaid, the majority of crypto losses this year have been attributed to key compromises and operational security features. The Coldcard exploit is an extreme example of the latter.
Moreover, the incident could push fence-sitters towards institutional and retail exposure to Bitcoin through spot Bitcoin ETFs.
However, self-custody advocates have pointed out that the exploit occurred because of a firmware bug, not a hardware flaw, arguing that self-custody is the safest way to store Bitcoin.
What Steps Can Coldcard Users Take
Coldcard users, especially those who have generated their seeds between March 2021 and Coinkite’s latest advisory, must follow the steps listed below.
- Check the Model and Firmware – If you own a Coldcard Mk2, Mk3, Mk4, Mk5, or Q and generated a seed between March 2021 and the latest update, the seed may be compromised.
- Update Firmware – Coinkite has released firmware updates for the affected devices. Mk2 and Mk3 users can update to version 4.2.0 and above. Mk4 and Mk5 users can upgrade to 5.6.0 and above, while Coldcard Q users can update to 1.5.0Q.
- Check Entropy – Coinkite’s advisory states that the seeds of users who have used the Add Dice feature and completed 50 private, independent rolls are not at risk. However, if you have used fewer than 50 rolls, or not used the Add Dice feature at all, your seed may be compromised.
- Recheck Passphrase – A BIP-39 passphrase adds another layer of security. However, users must ensure their passphrase is long, unique, and unrecorded. Shorter phrases cannot be deemed secure.
FAQs
What Caused The Coldcard Exploit
The root cause of the exploit was a bug that shipped in March 2021. The error altered how the firmware called its cryptographic library, causing it to revert to a weak software random number generator instead of relying on the Coldcard device’s source of entropy. This led to the key strength falling from the standard 128 bits to as low as 40 bits on some devices, making them susceptible to brute-force attacks.
Will Updating The Firmware Protect The Wallet From The Exploit
This is where things could get tricky for users. It is generally assumed that if the firmware has a bug, it can be updated to fix that bug. However, in Coldcard’s case, it’s only partially correct. A firmware update fixes the RNG issue moving forward, but does not retroactively fix seeds generated on the vulnerable software. Users should treat seeds generated between March 2021 and Coinkite’s latest update as compromised and move their funds after generating a new seed on an updated device.
Does The Hacker Need Physical Access To Exploit The Vulnerability
No, hackers can use brute-force attacks without needing access to the actual device.
Did The Exploit Impact Tapsigner, Satscard, Or Opendime Devices
No, these devices run on separate codebases and were not impacted by the exploit, which is limited to Mk2, Mk3, Mk4, Mk5, and Coldcard Q devices.
Has Anyone Claimed Responsibility For The Attack
No single entity has claimed responsibility for the exploit. Blockchain analysis revealed differences between transaction patterns, suggesting the involvement of multiple threat actors exploiting the same vulnerability.
Is My Coldcard Wallet Compromised
The Coldcard wallet is not compromised, and a firmware update fixes the vulnerability for new seeds. However, seeds generated between March 2021 and Coinkite’s latest update are vulnerable.
This article was originally published as The Coldcard Exploit: A Deep Dive Into One Of The Most Significant Hacks In Recent Memory on Crypto Breaking News – your trusted source for crypto news, Bitcoin news, and blockchain updates.
0
0
Securely connect the portfolio you’re using to start.





