A build error in Coldcard’s firmware drained $38 million in bitcoin in 25 minutes

1 hour ago 1



Coinkite says an attacker used AI to find a flaw its own AI review missed, exposing 500 wallets to a seed generation bug that reduced 128 bits of entropy to 40. Summary An attacker drained 594 BTC, approximately $38 million, from roughly 500 Coldcard hardware wallets in 25 minutes on July 31, exploiting a seed generation flaw present since March 2021. The bug reduced the effective entropy of Mk3 seeds from 128 bits to approximately 40 bits, making private keys guessable through brute force computation instead of cryptographic attack. Coinkite, the maker of Coldcard, believes the attacker used AI to discover the flaw in its open source firmware, and says its own AI audit of the same code weeks earlier found nothing. Every current Coldcard model is affected to some degree, with Mk4, Q, and Mk5 seeds estimated at roughly 72 bits of entropy instead of 128, and updating the firmware does not repair seeds already created. Block, Trezor, and Ledger have confirmed their products are unaffected, while the incident raises fundamental questions about whether hardware wallets can be trusted as the sole custodial layer for significant bitcoin holdings. The attack took 25 minutes. At 2:14 a.m. U...

Read Entire Article