Coldcard Security Flaw Leads to 594 BTC Theft
A firmware vulnerability in Coldcard hardware wallets allowed an attacker to drain nearly 600 Bitcoin from users.

BTCcoinbeat.news
BTC/USD live chart
LIVEA serious security vulnerability has led to the theft of approximately 594 Bitcoin. The incident occurred on Thursday when an attacker systematically drained funds from around 500 individual wallets in under thirty minutes. The stolen funds, valued at roughly 38 million dollars, have since been consolidated into a single address.
The breach stems from a flaw in how certain Coldcard hardware wallets generated private keys. Instead of using a random number generator, the affected firmware produced keys based on predictable timer states and call history. This error left private keys vulnerable to being recreated by an outside party. The issue impacts several models including the Mk3, Mk4, Q, and Mk5 devices.
Security experts warn that upgrading the firmware does not fix a key that was already generated using the flawed process. If a wallet was created while the device was running the problematic software, the seed remains insecure even after an update. Anyone who exported such a seed to another wallet is still at risk.
Users who hold funds on these devices should move their assets to a new wallet created on a secure, unaffected device. Coinkite noted that adding a BIP 39 passphrase can provide some protection, but migrating to a new seed is the safest path forward. Traders should remain cautious as investigators continue to track the movement of the stolen funds.
Prices update live from CoinMarketCap. Market data, not financial advice.
Market sentiment
Be the first to react
▍Comments (0)
No comments yet. Start the conversation!



