Coldcard's Random Numbers Got Too Friendly: 594 $BTC Walks Out the Door 🪦
Back to feed

Coldcard's Random Numbers Got Too Friendly: 594 $BTC Walks Out the Door 🪦

Canadian Bitcoin hardware maker Coinkite is warning users of its Coldcard Mk3 to migrate funds from any wallet whose seed phrase was generated on affected firmware, while security specialists examine a coordinated sweep that moved 594.48 $BTC from single-signature addresses. The losses, valued at approximately $38.3 million based on a Bitcoin price of $64,364.07 per CoinGecko, were drained from roughly 500 wallets within 25 minutes early Friday, with 562 $BTC since consolidated into a single address.

On Thursday, Coinkite said seeds created on an Mk3 running firmware version 4.0.1, released in March 2021, through 5.0.3, the final firmware supporting the device, may put funds at risk, while the Mk4, Q and Mk5 are not affected based on its early analysis. "Out of an abundance of caution," Coinkite urged affected users to generate a new seed on an unaffected device, verify its backup and receive address, send a small test transaction and only then move remaining funds. The company said its investigation is ongoing and promised a formal technical review, adding that affected seeds used with a BIP-39 passphrase face minimal risk, stressing the term refers to a passphrase rather than the Coldcard PIN.

In a technical breakdown published the same day, Coinkite said its firmware calls a function to fetch randomness, and two implementations of that function sat in the codebase with identical signatures: the hardware generator Coinkite wrote, and a software fallback inherited from MicroPython. A preprocessor guard checked only whether a setting was defined without testing its value, so the build completed against the fallback without complaint, with seed generation drawing on it since a March 2021 migration. Coinkite estimates the effective search space for an Mk3 seed at about 40 bits, against the 128 bits a seed is meant to have, while extra entropy from secure elements on the Mk4, Q and Mk5 lifts theirs to roughly 72 bits. Tapsigner, Opendime and Satscard use different code and are unaffected. Coinkite has shipped an emergency hotfix, version 5.6.0 for the Mk4 and Mk5 and 1.5.0Q for the Q, and noted that updating does not repair a seed already created on affected firmware; owners need a new seed generated on patched hardware, and the company recommends a strong BIP-39 passphrase, at least 99 dice rolls, or both. Mk3 owners, whose model is out of support, are pointed to a separate migration path.

The company said it has to assume "someone used AI to review previous versions of our firmware" in order to uncover the flaw, noting that a model run over its own code a few weeks earlier "did not find this bug or anything serious." "Attackers and defenders have the same tools," Coinkite wrote, but this time "it did not help us, and only helped the bad guys."

AnchorWatch CEO and co-founder Rob Hamilton said in a preliminary analysis on Friday that 1,324 unspent transaction outputs were swept across 500 transactions within a three-block window, moving 594.48 $BTC, and that all addresses involved were single-signature. "At a glance, this looks like there was flawed entropy in wallet generation somewhere along the way," Hamilton wrote. Separately, Wizardsardine CEO Kevin Loaec said his current hypothesis is that a low-entropy random-number generator, potentially in a software library, secure element or particular device batch or firmware version, produced wallet seeds with insufficient randomness, and suggested an attacker who knew of the flaw may have used an AI-generated script to brute-force affected wallets across only a limited range of BIP-84 derivation paths. That could explain why the sweep appears concentrated in native SegWit addresses and why some wallets were only partially drained, though Loaec stressed the theory remains unconfirmed and warned that wallets only partially drained may remain at risk.

Mentioned Coins

$BTC
Share:
Publishercryptonewsroom.xyz
Published—
CategorySecurity

Disclaimer: This content is for information and entertainment purposes only. It does not constitute financial, investment, legal, or tax advice. Always do your own research and consult with qualified professionals before making any financial decisions.

See our Terms of Service, Privacy Policy, and Editorial Policy.