Galaxy Digital analyzes Coldcard hack as losses climb past $111M

1 hour ago 2



Hardware wallets have long been sold on a simple promise: keep your keys offline, keep your Bitcoin safe. That promise just took a serious hit. A firmware vulnerability in Coldcard hardware wallets, produced by Coinkite, allowed attackers to drain roughly 1,596 to 1,719 BTC from thousands of addresses, with losses estimated between $100M and $111M. A suspected fourth wave of attacks, identified around August 3, added approximately 389 BTC to that total. Alex Thorn, from Galaxy Digital’s on-chain analysis team, confirmed the findings through on-chain forensics. The detail that makes this breach particularly brutal: victims followed every recommended security practice. No phishing. No key leakage. No user error. The firmware itself was broken. A flaw five years in the making The vulnerability traces back to a single firmware release. Coldcard version 4.0.1, pushed on March 17, 2021, introduced a bug in the device’s random number generator that caused wallet seeds to be generated with far lower entropy than expected. Some affected seeds carried as little as roughly 40 bits of entropy. To put that in plain terms: a well-secured Bitcoin wallet should be computationally impossible to gue...

Read Entire Article