Monday, August 3, 2026

COLDCARD wallet RNG flaw likely linked to $88 million Bitcoin theft

189
SHARES
1.5k
VIEWS
Sign up an get up to $1000 USDT!


Hand holding bitcoin

Researchers suspect {that a} vulnerability in COLDCARD {hardware} wallet firmware was exploited to steal an estimated $88.6 million in Bitcoin from 1000’s of wallets whose seeds have been generated utilizing a flawed random quantity generator.

Related articles

Digital asset analysis agency Galaxy Research says it recognized an preliminary wave of transactions that it believes was likely linked to the vulnerability, draining roughly 1,083 BTC, value $70.2 million, from 1,196 addresses on July 30.

The 41-minute assault occurred roughly 30 hours earlier than Coinkite publicly disclosed the flaw.

image

Each transaction used an similar hardcoded payment fee of 30 satoshis per digital byte and left no change output, making Galaxy imagine the attackers used an automatic device.

“Signature: each sweep paid an similar hardcoded 30.0 sat/vB — a 30-75x overpay vs the 0.4-1.0 sat/vB median that week — and left no change output, defined Galaxy.

“That appears like an automatic device spending keys it already held, not house owners transferring funds.”

On August 1, Galaxy Analysis recognized a second and third wave, elevating the estimated whole to 1,367 Bitcoin, value roughly $88.6 million, stolen from 4,585 addresses. The stolen Bitcoin remained within the attacker-controlled addresses on the time of its report.

Chainalysis discovered that the attacker prioritized high-value wallets, stealing roughly $30 million through the first ten minutes and taking $1.8 million from one sufferer.

The corporate stated this advised the attacker had recognized and studied the affected wallets earlier than starting the thefts.

Transactions for stolen COLDCARD assets over time
Transactions for stolen COLDCARD belongings over time
Supply: Chainalysis

Flaw in COLDCARD RNG

Block’s Bitcoin Engineering and Safety groups say that after seeing stories of Bitcoin being stolen from COLDCARD wallets, it labored with different researchers to analyze the gadget’s firmware and establish the underlying vulnerability.

Block says the researchers traced the problem to an integration error in COLDCARD’s random quantity era (RNG) code and disclosed their findings to Coinkite on July 30.

“COLDCARD firmware comprises an RNG integration error that causes ngu.random to use MicroPython’s deterministic Yasmarang fallback as a substitute of the STM32 {hardware} RNG,” explains Block’s report.

COLDCARD features a separate {hardware} random quantity generator, however an incorrect test within the firmware brought on it to use a deterministic software program generator as a substitute.

The fallback generator relied on the gadget’s microcontroller identifier and system timing values, which Block says are usually not cryptographically safe sources of randomness and could also be observable or reconstructable.

This allowed attackers to generate doable wallet seeds offline, decide their Bitcoin addresses, and examine them with addresses seen on the blockchain. A match would affirm the proper seed, permitting the attacker to generate the personal keys wanted to steal the funds.

A Coinkite advisory says affected seeds embody these generated on Mk2 and Mk3 firmware variations 4.0.1 by means of 4.1.9, Mk4 and Mk5 gadgets earlier than customary model 5.6.0 or Edge model 6.6.0X, and Q gadgets earlier than customary model 1.5.0Q or Edge model 6.6.0QX.

New firmware that fixes the flaw is on the market as model 4.2.0 or later for Mk2 and Mk3, 5.6.0 or later for normal Mk4 and Mk5 gadgets, 1.5.0Q or later for normal Q gadgets, and model 6.6.0X or 6.6.0QX for the corresponding Edge releases.

Nonetheless, it ought to be famous that updating the firmware doesn’t restore a seed that was beforehand generated.

Affected customers ought to confirm their present backup, set up the mounted firmware, generate and securely report a brand new seed, confirm the brand new wallet deal with on the gadget, ship a small take a look at transaction, after which transfer the remaining funds.

The previous backup ought to be retained till the migration is full and confirmed.

Coinkite says seeds supplemented with no less than 50 honest, unbiased, and personal cube rolls are usually not thought-about in danger from this flaw alone.

A powerful, distinctive BIP-39 passphrase additionally makes it tougher to exploit, however customers ought to nonetheless migrate as a result of it doesn’t restore the underlying seed. 

Coinkit says that their TAPSIGNER, OPENDIME, and SATSCARD merchandise are usually not affected as a result of they use completely different codebases.

Coinkite says it additionally destroyed all COLDCARD gadgets that have been awaiting cargo with the affected firmware.

Clients whose gadgets had already shipped have been contacted by e mail with the safety advisory and directions for migrating their funds.


article image

Safety groups log 54% of profitable assaults and alert on simply 14%. The remainder transfer by means of your surroundings unseen.

The Picus whitepaper reveals how breach and assault simulation assessments your SIEM and EDR guidelines so threats cease slipping by detection.

Get the whitepaper



Source link

Drive and walk to earn crypto!

Related Posts