00:00
Money for You
Money for You
USD/RUB
EUR/RUB
Cryptocurrency

Coldcard flaw exposes $116 million in Bitcoin to systemic theft

A critical firmware error in Coldcard hardware wallets has left approximately 1,816 Bitcoin, valued at $116 million, vulnerable to exploitation. The flaw, which persisted for over five years, reduced the entropy of generated seed phrases, allowing attackers to reconstruct private keys without needing physical access to the affected devices.

Coldcard flaw exposes $116 million in Bitcoin to systemic theft

The security failure stems from a configuration error introduced in firmware version 4.0.1, which caused Coldcard Mk2 and Mk3 devices to utilize a predictable software random-number generator instead of the intended hardware source. While Coinkite has since released patches, the fix does not retroactively secure existing wallets. Users whose seeds were generated with the flawed firmware must perform a complete migration to a new wallet, as the underlying weakness remains embedded in the initial recovery phrase regardless of subsequent updates.

According to TEXITcoin founder Bobby Gray, the incident highlights a dangerous reliance on automated security features. Users who manually supplemented the device's entropy with independent dice rolls remained unaffected by the vulnerability. While some Bitcoin holders have migrated assets to centralized exchanges like OKX in response to the theft, industry analysts argue this merely shifts risk to third-party custodians. As investigators at TRM Labs trace the stolen funds, the event has reignited debates regarding the complexities of self-custody versus the institutional reliance of regulated spot Bitcoin ETFs.

Share

Comments (0)

Leave a comment

No comments yet. Be the first!