Build with CoinStats’ all-in-one API. Learn more

EnglishDeutsch한국어日本語中文EspañolFrançaisՀայերենNederlandsРусскийPortuguêsTürkçeTracker portafoglioCriptovalutePrezziCrypto APIIntegrazioniNotiziaGuadagnaBlogNFTWidgetTracker di Portafoglio DeFiCrypto GamingRapporto 24hPress KitDocumenti API
CoinStats

Coldcard Releases Security Firmware After $130M Bitcoin Exploit

rialzista:

0

ribassista:

0

Coldcard Releases Security Firmware After $130M Bitcoin Exploit

Coldcard maker Coinkite has released a major security firmware update after attackers exploited weak seed generation to steal more than 1,778 BTC from thousands of Bitcoin addresses, with earlier estimates placing the broader attack near $130 million.

The August 20 release introduces firmware 5.6.1 for Mk4 and Mk5 and 1.5.1Q for Q, following three weeks of security review after the July 31 hotfix. Every newly generated seed now requires users to contribute their own randomness through at least 65 key presses with unpredictable timing, 50 physical dice rolls or 128 physical coin flips.

Users whose seeds were generated on affected firmware between March 2021 and July 2026 still need to create a new seed and move their Bitcoin. Installing the latest firmware does not repair a recovery phrase created with insufficient entropy.

Coldcard Adds User Randomness And New Signing Checks

The new seed-generation process combines the user input with fresh entropy from Coldcard’s STM32 hardware random-number generator and both secure elements. Coinkite also replaced its Yasmarang backup pseudo-random generator with SHA-256 Hash_DRBG and added boot-time checks designed to stop the device if the intended hardware RNG path is not reached.

The original seed-generation flaw emerged from firmware introduced in 2021. Affected Mk2 and Mk3 seeds could contain only about 40 bits of effective entropy, while later Mk4, Mk5 and Q devices could fall to roughly 72 bits instead of the intended 128. Attackers could reconstruct candidate seeds offline and compare derived addresses against the Bitcoin blockchain without stealing the physical device or recovery phrase.

Coldcard has also added a second check of staged partially signed Bitcoin transactions immediately before signing. A transaction modified by a compromised USB-connected computer after the user reviews it will now stop with a “Transaction modified” warning. The release also tightens USB access, firmware validation, Delta Mode isolation, wallet backups and RNG fault handling.

Confirmed Coldcard Losses Reach 1,778 BTC

The theft initially expanded through several distinct attack waves. A subsequent third wave pushed the observed total above 1,367 BTC before more victims and attacker footprints were identified.

By August 14, Galaxy Research had directly contacted 190 victims and attributed 1,778.84 BTC worth $112.7 million to more than 8,600 addresses with high confidence. The figure excludes medium-confidence activity, including a suspected fourth wave. Adding those candidate thefts would raise the potential total to 2,417.35 BTC, worth about $153 million at the time.

The earlier loss estimate near $132 million emerged as Galaxy identified at least 15 attackers exploiting the same weak-seed problem. No confirmed new attack footprint has been dated after August 6, although additional victims have continued reporting earlier losses.

About 1,531 BTC from the high-confidence theft set remained unmoved as of Galaxy’s latest analysis. Roughly 246 BTC had moved afterward, with about 65% of that amount entering CoinJoin transactions.

Law Enforcement Investigates As Users Migrate Bitcoin

Coinkite said law enforcement authorities are investigating the thefts and working to identify those responsible. Galaxy has supplied attacker addresses to law enforcement agencies, exchanges and investigation firms to support tracing and potential intervention if stolen Bitcoin reaches centralized services.

The exploit has also accelerated broader review of Bitcoin software. The Bitcoin Red Team recently produced thousands of security findings across hundreds of open-source projects using human researchers and AI-assisted analysis, while Coinkite used external researchers and AI models during its own three-week firmware review.

Affected Coldcard users should first install fixed firmware, generate and verify an entirely new seed, confirm a receiving address and then move the Bitcoin onchain. Importing the old recovery phrase into another wallet leaves the vulnerable seed unchanged.

Coinkite currently recommends firmware 5.6.1 for Mk4 and Mk5 and 1.5.1Q for Q. Mk2 and Mk3 users require version 4.2.0 or later, and any affected seed must still be replaced separately from the firmware upgrade.

The post Coldcard Releases Security Firmware After $130M Bitcoin Exploit appeared first on Crypto Adventure.

rialzista:

0

ribassista:

0

Gestisci cripto, NFT e DeFi in un unico luogo

Connetti in sicurezza il portafoglio che usi per iniziare.