▼ Bear
Impact
100 · High
Due to a firmware flaw in Coldcard devices, approximately 2,055 BTC (worth 130 billion Korean won) has been affected
BTC
CryptoSlate · 1d agoView original ↗

Block's Bitcoin engineering and security team, along with independent Bitcoin Core developers, have identified the large-scale loss incident affecting CoinKite ColdCard wallets as being caused by a specific firmware flaw. This flaw caused the system to use MicroPython's deterministic Yasmarang fallback path instead of the STM32 hardware random number generator (RNG) during the seed generation process. As a result, the cryptographic randomness of the seeds generated in the Mk2 and Mk3 models was reduced to a small set that an attacker could exhaustively search. The Mk4, Q, and Mk5 models also generated only about 72 bits of entropy, significantly below the design target of 128 bits.
The problematic firmware versions range from 4.0.1 to 4.1.9, and were distributed by CoinKite over a period of approximately five years, from 2021 to July of this year. Despite the availability of the source code, the flaw remained undetected during this period. According to CoinKite's technical notes, previous reviews confirmed the presence of the correct hardware RNG in the firmware binary, but it was not verified whether the seed generation routine actually reached that path.
The extent of the damage continues to grow. In the initial wave, approximately 594 BTC were stolen from around 500 wallets. Subsequently, researchers identified at least three additional waves, resulting in losses affecting over 4,500 addresses, totaling approximately 1,367 BTC (worth around $89 million at the time). On August 3rd, there were reports of a potential fourth wave, suggesting that the total losses could reach approximately $114 million. An update from Lookonchain and Galaxy Research on August 4th estimated the losses at 2,055 BTC, or approximately $130 million, affecting over 7,700 addresses. However, Alex Sun of Galaxy Digital cautioned that blockchain patterns alone could not definitively confirm the association between certain addresses and the vulnerable ColdCard firmware.
Users who had set strong BIP-39 passphrases and those who had rolled the dice more than 50 times to add external entropy were not directly affected by this specific vulnerability. Because BIP-39 passphrases are combined with mnemonics to derive a separate wallet seed, different wallets are created even if the base words are the same. Nevertheless, CoinKite recommends that these users also migrate. Andrew Manuca, CISO of J.P. Morgan, stated:
This is an AI summary. Read the full article at the source.