Loading market data...
Back to Feed
CRYPTO NEWS

How a bug in Coldcard’s code went unnoticed for years, leading to $100 million in hacked funds

Reported by CoinDesk · AI-assisted summary by ChikoCorp AI News Desk

Published on CryptoNews: Source published: 2 min read
Visit source

AI-generated summary based on the linked source; not independently verified. This is not investment advice. Verify market-moving details at the original publisher before acting. See our editorial policy, AI content policy, and financial disclaimer.

$100 million$1.17 million

Summary

A critical bug in Coldcard hardware wallets’ seed generation software went unnoticed for years, enabling attackers to steal approximately 1,596 bitcoin—worth over $100 million—from about 7,300 addresses. The vulnerability stemmed from a 2021 firmware update that caused the wallets to use a weak randomness source for seed creation, substantially reducing the pool of possible keys. Coldcard manufacturer Coinkite has released a fixed firmware and is supporting affected customers, but the breach underscored risks in self-custody hardware wallets.

Why it matters

This incident challenges the fundamental security assumption of hardware wallets—that private keys never leave an offline device and cannot be hacked remotely. The flaw shows that even air-gapped hardware wallets are vulnerable to software bugs in key generation processes. The hack affected thousands of users and highlights an often overlooked counterparty risk in self-custody: trusting the wallet manufacturer’s code integrity.

Key context

Hardware wallets like Coldcard are designed as cold wallets keeping private keys offline, contrasting with software or hot wallets connected to the internet. Coldcard’s 2021 firmware update introduced new code intended to improve features but inadvertently caused a configuration error, leading to the use of a weak software random number generator instead of a hardware randomness source. This reduced the cryptographic entropy of keys from 128 bits to around 72 bits, drastically lowering security.

Key numbers and entities

Coinkite is the Toronto-based company behind Coldcard wallets. Jonathan Goodman lost 18.25 bitcoin, worth over $1.17 million at the attack time. Galaxy Research estimated a total theft of 1,596 bitcoin, valued over $100 million across 7,300 addresses. The flaw appeared in firmware version 4.0.0 released March 17, 2021. At least 15 distinct attackers exploited the bug, according to Galaxy Research head Alex Thorn.

What remains unclear

Coinkite has not responded publicly to some investigative claims, including the code authorship attribution to co-founder Peter Gray. The company has promised a detailed account of the failure but has not yet provided one. It is also unclear exactly how many users remained exposed before installing the patched firmware or the full scope of user losses beyond reported estimates. The source does not flag additional open questions beyond these points.

Read the original source

> JOIN THE ALPHA

Get a free crypto news briefing in your inbox. No fake subscriber counts — just the latest source-backed headlines we cache.

>
[ENCRYPTED][NO_SPAM][UNSUBSCRIBE_ANYTIME]