The record
Written from the 1 report below. Nothing here is unsourced.
- A firmware flaw in Coinkite's Coldcard Bitcoin hardware wallets, introduced in a March 2021 update that routed seed generation to a weak software random number generator instead of the chip's hardware one, has enabled large-scale theft.
- An attacker drained 1,196 addresses in 41 minutes on July 30 for about $70 million, and Galaxy Research has since identified two more suspected waves, raising estimated losses to roughly $88.6 million across 4,585 addresses.
- Coinkite shipped emergency firmware for all affected models on July 31, but installing it does not fix an already-generated seed, so owners of exposed seeds must create new ones on patched firmware and move their coins.
- Exposure depends on which firmware version was running when a seed was created, and no one has yet computationally confirmed every drained address came from weak Coldcard entropy or named the attacker.
What to watch next
- Whether additional sweep waves are detected, as Galaxy says the activity is ongoing and Wave 3 may involve a different operator.
- Any computational confirmation that drained addresses were generated with weak Coldcard entropy, which the report says has not yet been done.
- Whether the roughly 600 suspected attacker-controlled addresses reported to federal investigators and compliance firms lead to identified or recovered funds.
Coverage1
1 report
English national1
All filed from India
Named Canada · Bitcoin · Coldcard · Block · Coinkite · Coinspect · Galaxy Research · Ill Bloom
The 1 report is listed beside the record.
Ask this story
Answers cite the reports above, or say they can't.
