DistantNews
Support us
Coldcard wallet flaw leads to $115 million theft, exposing trust issues
๐Ÿ‡ฆ๐Ÿ‡น Austria /Technology

Coldcard wallet flaw leads to $115 million theft, exposing trust issues

From Die Presse · () German

Translated from German, summarized and contextualized by DistantNews.

At a glance

News Named sources Outcome reported
  • Hackers exploited a flaw in Coldcard hardware wallet firmware, allowing them to guess predictable seed words and steal $115 million.
  • The vulnerability exploited a lack of true randomness in the automatic seed word generation process.
  • This incident highlights the risks of trusting manufacturers and the importance of verification, even for security-conscious users.

The Bitcoin network itself remains secure, but a significant vulnerability in certain versions of the Coldcard hardware wallet has led to the theft of approximately $115 million. Hackers exploited a flaw in the firmware's code, specifically targeting the automatic generation of seed words (backup phrases). This flaw resulted in a lack of true randomness, making the seed words mathematically predictable and guessable by attackers.

This incident is particularly concerning because the victims were not novices. They were described as security-conscious Bitcoin maximalists, long-term holders, and technically savvy users who prioritized self-custody. They believed they were adhering to the principle of "Not your key, not your coin," entrusting their Bitcoin to supposedly uncrackable hardware devices and ensuring their private keys never went online. Their mantra, "Don't trust, verify," led them to avoid third-party services like crypto exchanges.

However, the hackers gained access without needing physical proximity to the devices. By exploiting the firmware error, they could deduce the seed words and subsequently drain the wallets. This breach underscores a critical lesson: even users who meticulously follow security best practices can be vulnerable if the underlying technology they rely on has hidden flaws. The assumption that publicly auditable firmware code would inherently prevent such critical errors proved false.

Only users who had distrusted the manufacturer's random number generator and manually generated their seed words were safe. This event challenges the self-perception of dedicated Bitcoin maximalists and demonstrates that there is no single, universally foolproof method for securing Bitcoin. For individuals who are not extremely technically proficient, the reliance on hardware manufacturers, despite their security claims, becomes a necessary, albeit now demonstrably risky, trust factor.

DistantNews Editorial

Originally published by Die Presse in German. Translated, summarized, and contextualized by our editorial team with added local perspective. Read our editorial standards.