Coldcard Flaw Tied to $38M Bitcoin Heist as Predictable Seed Generation Exposed Wallets

AI مارکیٹ کا خلاصہ
A critical Coldcard seed-generation flaw enabled rapid theft of ~594 BTC from ~500 wallets, undermining confidence in hardware wallet security and operational practices around seed creation. Although emergency firmware updates are available, compromised seeds cannot be fixed in-place, forcing users to migrate funds and potentially creating near-term on-chain churn. The incident also broadens audit scope to related key material, raising counterparty and custody-risk awareness across the crypto market.
اثر کی سطح
● ہائی
متاثرہ اثاثے
BTC/USDT-3.19%
AI تجزیاتی سمجھ · BTC/USDTAI تجزیاتی سمجھ
▼ Bearish
ابھی ٹریڈ کریں
⚠️ AI سے تیار کردہ تجزیاتی سمجھ خبروں کے مواد پر مبنی ہے اور صرف معلوماتی مقاصد کے لیے فراہم کی گئی ہے۔ یہ سرمایہ کاری کا مشورہ نہیں ہے اور نہ ہی BingX کے خیالات کی نمائندگی کرتی ہے۔ سرمایہ کاری میں رسک شامل ہے۔ براہ کرم ذمہ داری سے ٹریڈ کریں۔
An attacker siphoned roughly 594 BTC—about $38 million—from around 500 Coldcard single-signature wallets in a tightly coordinated sweep early Friday, completing the theft in just 25 minutes. On-chain analysis shows the funds were moved between 01:31 and 01:56 UTC, spread across 500 transactions within a three-block window. Investigators traced 562 BTC to a single address that has not moved so far. Many of the impacted wallets appeared to have been dormant for years before the coordinated withdrawals began. Coinkite said the incident stems from a firmware issue introduced in March 2021 that undermined randomness during seed generation. A build setting caused devices to bypass the hardware random number generator, while a related library check only verified the setting's presence rather than whether it was enabled. As a result, key generation could fall back to software seeded with chip serial numbers and clock registers—values that are not secret and can be modeled—shrinking the effective search space that should make private keys impractical to guess. Risk depends on the firmware version used when a wallet's seed was created, not when the hardware was purchased. Coinkite warned that users who generated a seed on a COLDCARD Mk3 running firmware 4.0.1 or later may be exposed. The company said Mk4, Q and Mk5 are not affected based on early analysis, and it issued emergency firmware updates for Mk4, Mk5 and Q. Coinkite emphasized that updating firmware cannot repair a seed created under vulnerable conditions. Users must generate a fresh seed and move funds, because patches cannot retroactively restore compromised entropy. Suggested safeguards include using a strong BIP39 passphrase, generating entropy with at least 99 dice rolls, or both. Mk3 owners face a separate, potentially more complex migration path to secure any remaining balances. The company also said it suspects artificial intelligence may have been used to review older versions of its open-source firmware and identify the weakness at scale, though it described this as an assumption rather than confirmed attribution. Coinkite noted that its own AI-assisted review weeks earlier did not flag the issue. The ongoing security review extends beyond wallet seeds: the same flawed generator may have impacted paper wallet keys, seed-splitting masks, cloning keys and Key Teleport transfers, expanding the potential exposure beyond the 594 BTC already stolen.