CyrilXBT|Jul 31, 2026 15:27
$38 MILLION IN BITCOIN WAS JUST STOLEN FROM COLDCARD HARDWARE WALLETS. IN UNDER 25 MINUTES.
Not a phishing attack. Not a hack of the device itself. A firmware bug in the wallet's own random number generator.
Root cause: a macro that should have enabled the hardware's true random number generator was misconfigured, and a supporting library only checked whether the setting existed, not whether it was actually working. The fallback silently used MicroPython's software generator, seeded by the chip's serial number and internal clock, neither of which is secret.
Roughly 594 BTC drained from about 500 single-signature wallets. Affects Coldcard Mk3 devices running firmware 4.0.1 or later. Coinkite is urging affected users to move funds to a freshly generated seed immediately.
Even a device built specifically to keep your keys offline can still fail if the randomness underneath it was never truly random.(CyrilXBT)
Share To
Timeline
HotFlash
APP
X
Telegram
CopyLink