Coldcard Crack Costs Crypto Millions in Minutes
A sophisticated cyberattack has exposed a critical security weakness in cryptocurrency hardware wallets, with hackers stealing hundreds of Bitcoin within minutes. Initial reports indicated that 584 Bitcoin—worth approximately 38 million dollars—had been stolen from 500 cryptocurrency wallets during a 25-minute attack last Friday.
However, subsequent investigations by several international media outlets suggest the breach was even more severe. Within just 41 minutes, attackers reportedly drained approximately 70.2 million dollars' worth of Bitcoin from 1,196 separate wallets. The attack has been linked to a major security vulnerability in Coldcard, the Bitcoin hardware wallet developed by Canadian company CoinKite. All affected wallets reportedly contained at least 0.15 Bitcoin and were configured as single-signature wallets.
How the Attack Happened
Every cryptocurrency wallet relies on a seed phrase—a secret sequence of words that serves as the master key for recovering access to digital assets. These seed phrases are intended to be generated using highly secure random number generators, making them effectively impossible to predict.
However, a report by Block's Bitcoin Engineering and Security team revealed that Coldcard's firmware bypassed its dedicated hardware-based random number generator and instead relied on a weaker software algorithm.
According to the report, the wallet generated its secret values using Yasmarang, a weak pseudorandom number generator included in MicroPython. Because the generated values were predictable, attackers were reportedly able to reconstruct wallet seed phrases offline and ultimately gain access to users' Bitcoin holdings.
Who Is at Risk?
Coldcard is designed as an offline hardware wallet, allowing users to store Bitcoin without maintaining a direct internet connection. Owners of several older models—including the MK2, MK3, MK4, Q, and MK5—have reportedly been affected by the vulnerability.
CoinKite has stated that its newer hardware models are not affected by the flaw. However, the company warned that simply updating the firmware on older devices does not eliminate the risk associated with seed phrases generated before the fix. Users are therefore advised to update their firmware and create entirely new wallets with newly generated seed phrases.
The incident underscores growing cybersecurity concerns within the cryptocurrency sector. During the first half of this year alone, approximately 1 billion dollars (around 9,547 crore taka) worth of cryptocurrency assets were reportedly stolen, highlighting persistent weaknesses in digital asset security.
//DBTech/BMT/OR//





