CYBERSECURITYTRACKER
TRACKING6,767 stories in this site build1,408 vulnerability news stories in this site build
Permanent story citation

Coldcard Hardware Wallet Flaw Linked to $70 Million Bitcoin Theft in 41 Minutes

This page keeps the story as Cybersecurity Tracker first published it. If the tracker later corrects it, the correction appears below the original and never replaces it.

Back to newsStory 3687

As cited

Copy frozen at (site build).

vulnerabilities

Coldcard Hardware Wallet Flaw Linked to $70 Million Bitcoin Theft in 41 Minutes

An attacker exploited a firmware flaw in Coldcard hardware wallets to drain 1,196 Bitcoin addresses of approximately 1,082.65 BTC (worth $70.2 million) in 41 minutes on July 30. Galaxy Research traced the theft to a March 2021 firmware integration error that routed seed generation through a deterministic software pseudorandom number generator (PRNG) instead of a cryptographically secure one.

Why it matters: Coldcard users and Bitcoin custodians need to assess whether affected firmware versions were deployed in their deployments and rotate or verify key material, as predictable seed generation compromises the security guarantees of hardware wallet isolation.

Source published
First seen by Cybersecurity Tracker

Source attribution

Glossary