Block Links $38M COLDCARD Bitcoin Hack to Blockchain Services Provider
AI Market Summary
Block traced a 594 BTC (~$38M) COLDCARD-related theft to a blockchain services provider, tied to a March 2021 firmware bug that disabled the hardware RNG and enabled seed replication on affected Mk3/Mk2 devices. The fast 25-minute drain suggests precomputation and operational sophistication. While immediate price impact was limited, the event highlights latent self-custody and supply-chain risk, potentially increasing near-term security scrutiny across Bitcoin wallets.
Impact level
● Medium
Affected assets
BTC/USDT-2.98%
AI Insight · BTC/USDTAI Insight
● Neutral
Trade now
⚠️ AI-generated insights are based on news content and are provided for informational purposes only. They do not constitute investment advice or represent the views of BingX. Investing involves risk. Please trade responsibly.
Block said its engineering team has identified the party behind the COLDCARD hardware wallet exploit, tracing the attacker's activity to a blockchain services provider involved in the theft.
The breach occurred on July 30 and emptied about 594 BTC—roughly $38 million—from around 500 wallets in a 25-minute span between 01:31 and 01:56 UTC.
A firmware flaw dating back five years enabled the attack. Block said the issue originated in a March 2021 update, firmware version 4.0.0, which disabled the hardware random number generator (RNG) on affected devices. In its place, the wallet relied on a predictable software fallback that used non-secret seed values. An attacker with knowledge of the weakness could reproduce wallet seeds using device-specific metadata.
The impacted devices were mainly COLDCARD Mk3 units, along with some Mk2 models where seeds had been generated under the compromised firmware. Block said the attacker appears to have held the information for years and then targeted dormant accounts. The narrow execution window points to extensive preparation, including precomputing vulnerable seeds and automating the drain.
Block and COLDCARD maker Coinkite coordinated what they described as an urgent disclosure after linking the on-chain trail to the blockchain services provider. Coinkite issued an immediate advisory for users of Mk3 and older models that generated seeds under the affected firmware. Its initial assessment said newer devices—including Mk4, Q, and Mk5—are not impacted by the RNG issue.
Coinkite advised users to generate entirely new seeds on unaffected hardware and move funds immediately.
Bitcoin was trading above $64,000 at the time, and market reaction was limited. The company noted that users who installed v4.0.0 in March 2021 believed they were improving security, but instead created seeds under a weakened RNG.