Bitcoin Wallets at Risk After Critical Coldcard Security Bugs Get Exposed

CN
U.today
Follow
5 hours ago

Bitcoin self-custody users are being urged to move their funds after Block disclosed two critical vulnerabilities in multiple generations of Coldcard hardware wallets. 


Block's engineering and security teams started getting reports of Bitcoin being remotely stolen from non-Bitkey wallets and began an investigation. 


It turned out that Coldcard Mk2, Mk3, Mk4, Q, and Mk5 devices have security flaws. That said, the company has clarified that none of its products, including Bitkey, were affected. 


HOT Stories Can XRP Overcome Pressure? Zcash (ZEC) Might Bounce to $500, Did Hyperliquid (HYPE) Lose Its Importance? Crypto Market Review Crypto Is for Crooks, Dem Senator Says

Over 1,000 BTC potentially exposed to theft 


According to Block, the attack initially targeted single-signature wallets and took place over roughly an hour, but researchers warned the campaign is likely still active. 


The company said wallets protected with weak 25th-word passphrases and some multisignature setups could also be at risk.


The first vulnerability affects the Coldcard Mk2 and Mk3 firmware. In this case, a coding error caused wallet generation to rely on predictable values instead of sufficient hardware-generated randomness. 



You Might Also Like
Mon, 07/27/2026 - 15:48 Bitcoin Difficulty Set for First Annual Drop in 17 Years: What It Means for BTC PriceByGamza Khanzadaev

For newer Mk4, Q, and Mk5 devices, Block said the firmware attempted to improve entropy during boot using secure-element input. However, a flaw reduced that additional randomness to just 32 bits. 


Simply importing an affected seed into another wallet does not eliminate the threat. The compromised seed remains vulnerable if a wallet was created on vulnerable Coldcard firmware.  


Block said it privately disclosed its findings to Coldcard maker Coinkite and later made the findings public. 


"Personally I recommend that anyone affected move funds as soon as they can safely do so," Block engineer Max Guise wrote on X. 


What is notable is that the attack may be larger than initially believed. Security engineer Clay Garrett said researchers identified 695 earlier transactions that matched the same on-chain fingerprint. These transactions account for an additional 488.11 BTC.


The total amount potentially stolen would rise to 1,082.59 BTC, according to Block's preliminary analysis. 


免责声明:本文章仅代表作者个人观点,不代表本平台的立场和观点。本文章仅供信息分享,不构成对任何人的任何投资建议。用户与作者之间的任何争议,与本平台无关。如网页中刊载的文章或图片涉及侵权,请提供相关的权利证明和身份证明发送邮件到support@aicoin.com,本平台相关工作人员将会进行核查。

Share To
APP

X

Telegram

Facebook

Reddit

CopyLink