On July 30, a swift cyberattack drained nearly 600 BTC, around $38 million, from about 500 COLDCARD hardware wallets in a span of just 25 minutes. Block's engineering team has tracked the culprit back to a blockchain services provider, shedding light on a complex scheme rooted in an old firmware vulnerability.
A Hidden Flaw from 2021 Enabled the Theft
The breach exploited a weakness introduced in March 2021 with COLDCARD's firmware version 4.0.0. This update disabled the hardware random number generator, replacing it with a predictable software fallback. Because of this, attackers could reconstruct wallet seeds using device-specific information. The flaw primarily affected Mk3 devices and some Mk2 models that generated seeds under the compromised firmware.
The attacker appeared to have quietly held this knowledge for years, focusing on dormant wallets. The rapid 25-minute attack window implies thorough preparation with precomputed vulnerable seeds and automated scripts to drain funds efficiently.
Coordinated Response to Limit Damage
Block's engineers worked closely with Coinkite, the maker of COLDCARD, to trace on-chain activity to a blockchain services provider involved in the theft. This partnership led to an urgent, controlled disclosure of the vulnerability ahead of public technical details. Coinkite promptly advised users of Mk3 and older devices to generate new seeds using unaffected hardware and transfer their funds immediately. Fortunately, newer models like Mk4, Q, and Mk5 were not impacted by this RNG flaw.
Bitcoin hovered above $64,000 during the attack, which surprisingly caused little market disruption. Still, the incident raises concerns about long-dormant vulnerabilities in hardware wallets and the importance of cautious firmware updates.
This content is for informational purposes only and does not constitute financial advice.



