Coldcard Hardware Wallet RNG Flaw Linked to $88.6 Million Bitcoin Theft

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Spread the love

A firmware flaw in Coldcard hardware wallets has been linked to the theft of approximately $88.6 million in Bitcoin. Attackers exploited a compromised random number generator, allowing them to reconstruct victims’ private keys without ever accessing their devices.

Digital asset research firm Galaxy Research first noted unusual activity on July 30, when an attacker drained about 1,082.65 BTC, valued at around $70.2 million, from 1,196 addresses in a rapid sweep lasting just 41 minutes.

By August 1, Galaxy detected additional waves of transactions, bringing the total theft to 1,367.05 BTC, worth approximately $88.6 million, taken from 4,585 addresses.

The first two waves displayed similar transaction patterns, suggesting they likely originated from a single operator. In contrast, the third wave showed sufficient differences to suggest either revised tools or a separate attacker exploiting the same vulnerability.

Unlike most hardware wallet attacks, which typically involve phishing, malicious firmware installation, or physical access to the device, this exploit targeted the wallet creation process itself.

The payments firm Block’s Bitcoin Engineering and Security teams traced the issue to a code change made on March 1, 2021, that caused Coldcard’s production configuration to turn off the STM32 hardware random number generator.

A faulty check in the libngu library only verified whether a configuration macro was defined, not whether it was enabled, causing the system to default to MicroPython’s deterministic Yasmarang software generator, seeded from the device’s UID and timer state.

Attackers consolidated 1,082 BTC from 1,196 Bitcoin wallets into four unmoved addresses (Source : Glxyresearch )

As a result, seed generation was no longer genuinely random. Coinkite, the Canadian manufacturer of Coldcard, estimated that the effective entropy collapsed to approximately 40 bits on Mk3 devices and about 72 bits on Mk4, Mk5, and Q models.

This was far below the 128 bits typically expected from a standard BIP-39 recovery phrase. With such a low entropy pool, attackers could regenerate candidate seeds offline, derive their corresponding Bitcoin addresses, and cross-check them against public blockchain data to identify which wallets held funds.

Coinkite’s advisory indicates that Mk2 and Mk3 devices running firmware versions 4.0.1 to 4.1.9 are affected by the vulnerability. Mk4, Mk5, and Q devices running any version before 5.6.0, 5.6.0, and 1.5.0Q, respectively, are also considered at risk, albeit at a higher entropy level.

According to a post on X by Galaxy Research, exposure depends on the firmware version used when a wallet’s seed was first generated not the firmware currently installed. Wallets seeded before March 2021 or created with 50+ dice rolls or a strong BIP-39 passphrase are not considered at risk.

Coinkite released emergency firmware patches on July 31, including version 4.2.0 for Mk3, 5.6.0 for Mk4 and Mk5, and 1.5.0Q for Q devices. However, the company emphasizes that updating the firmware will not fix any seeds that have already been compromised.

Affected users are advised to install the patched firmware, generate a new seed, verify the new address on the device, send a small test transaction, and then migrate their remaining funds immediately.

Security researchers also suggest that multi-signature setups spanning devices from different manufacturers would have been resilient against a flaw isolated to a single vendor’s random number generator implementation.

 Strengthen Your SOC by Accelerating Threat Detection & Rapid Investigations. -> Integrate ANY.RUN With Your SOC Now.