
Coldcard Hardware Wallet Flaw Leads to $70 Million Bitcoin Theft
CryptocurrencyHackingVulnerabilitiesHardwareSecurity
On July 30, an attacker drained 1,196 Bitcoin addresses in 41 minutes, stealing 1,082.65 BTC valued at approximately $70.2 million at the time. The theft was linked to a firmware flaw in Coldcard, a Bitcoin-only hardware wallet manufactured by Canadian company Coinkite. Galaxy Research traced the incident to a March 2021 firmware integration error that misrouted seed generation to a deterministic software pseudorandom number generator (PRNG). No CVE ID was mentioned in connection with the vulnerability. The attack exploited the flaw to compromise private keys associated with the affected wallets.