Coldcard exploit drains over 1,367 BTC from air-gapped wallets, shaking self-custody confidence

1 hour ago 2



The whole point of an air-gapped hardware wallet is that it never touches the internet. Your keys stay offline, safe from hackers, malware, and all the digital gremlins that haunt crypto holders at night. Coldcard, one of the most trusted names in Bitcoin self-custody, built its reputation on exactly that promise. That promise just took a serious hit. A firmware vulnerability present in Coldcard devices since March 2021 has been exploited to drain approximately 1,367 BTC, worth roughly $88.6 million to $89 million, from more than 4,500 wallets. The exploit didn’t require internet access to the device. It targeted the randomness used to generate recovery seeds, making them predictable enough for an attacker to reproduce offline. How the exploit worked The vulnerability existed in Coldcard firmware versions 4.0.0 through 5.0.3. A critical firmware change made in March 2021 inadvertently caused the device to default to a predictable software Random Number Generator for seed generation instead of utilizing the hardware-based True Random Number Generator, fundamentally undermining the wallet’s security premise. Security experts at Block investigated and revealed the predictable fallback...

Read Entire Article