A firmware flaw affecting several generations of Coldcard hardware wallets has resulted in one of the largest known thefts involving self-custodied Bitcoin. Blockchain researchers estimate that attackers have stolen well over 1,500 BTC, valued at more than $100 million, by exploiting recovery phrases generated on vulnerable firmware versions. Investigators believe the campaign is still ongoing, and security experts continue to identify additional affected wallets.

 

 

The incident has drawn attention because it did not involve a vulnerability in Bitcoin itself. Instead, attackers exploited a weakness in the software responsible for creating wallet recovery phrases. Bitcoin’s cryptographic algorithms remain secure, but wallets generated using flawed firmware could produce recovery seeds that were far more predictable than intended.

Every hardware wallet creates a recovery phrase, usually consisting of 12 to 24 words, which acts as the master backup for all funds stored in the wallet. That phrase is generated from random data, and the quality of the randomness determines how difficult it is for anyone else to reproduce the same wallet.

According to Coinkite, the manufacturer of Coldcard, certain firmware releases introduced in 2021 contained a bug that reduced the amount of entropy, or randomness, used during seed generation. As a result, some wallets were created with recovery phrases that could be reconstructed using large-scale offline computation. Rather than attacking Bitcoin’s encryption, the attackers generated enormous numbers of possible recovery phrases and compared the resulting wallet addresses with addresses visible on the public blockchain until matches were found.

Once a matching recovery phrase was identified, the attackers could recreate the victim’s private keys without ever obtaining the physical hardware wallet. They could then authorize transactions from another device and transfer the bitcoin to wallets under their control.

Researchers tracking the thefts believe the attacks have occurred in multiple waves over several days, with new victims continuing to emerge as blockchain analysis progresses. While the first large-scale thefts appear to have been coordinated by a single operator, later activity suggests that multiple threat actors may now be exploiting the publicly disclosed vulnerability. Because the weakness became widely known after the initial attacks, security researchers warn that opportunistic attackers may continue searching for vulnerable wallets.

Updating a Coldcard device does not automatically remove the danger. The flaw affects the recovery phrase generated when the wallet was first created, meaning existing seeds remain vulnerable even after patched firmware is installed. For that reason, Coinkite has instructed users whose wallets may have been created with affected firmware to generate an entirely new recovery phrase and transfer their bitcoin into a newly created wallet. Simply importing the existing seed into another hardware wallet does not solve the problem because the compromised recovery phrase remains unchanged.

The incident has also reinforced the value of layered security. Publicly documented thefts have involved single-signature wallets, where one recovery phrase is sufficient to spend funds. Multisignature wallets, which require multiple independent keys to approve a transaction, provide additional protection because compromising a single recovery phrase does not grant complete control over the assets.

Another question raised by the incident is whether artificial intelligence played a role in discovering the flaw. Coinkite has suggested that someone may have used AI tools to analyse its publicly available source code, although the company has emphasized that this is only a hypothesis. No public evidence has confirmed that AI was used to identify or exploit the vulnerability.

The Coldcard incident has become a significant example of how weaknesses in wallet software can undermine otherwise secure hardware. Although Bitcoin’s core protocol was never compromised, the flaw demonstrates that the security of self-custodied cryptocurrency depends just as much on the software generating recovery seeds as it does on the cryptography protecting private keys.

Leave a Reply