Coldcard’s Hidden Bug Since March 2021: $70 Million in Bitcoin Vanish in 41 Minutes

$70M Bitcoin stolen due to a Coldcard hardware wallet firmware bug from March 2021. Learn about the flaw, affected devices, and required security actions.

Coldcard’s Hidden Bug Since March 2021: $70 Million in Bitcoin Vanish in 41 Minutes
Vulnerabilities

Illustrative image generated with AI

The July 30 Theft: 1,196 Addresses Drained with One Signature

On July 30, between 18:39 and 19:20 UTC, 1,196 Bitcoin addresses were drained one after another. The flurry lasted just 41 minutes, netting 1,082.65 BTC, worth about $70.2 million at the time. Galaxy Research mapped the operation and linked it to a vulnerability in the firmware of Coldcard hardware wallets, made by the Canadian company Coinkite.

All transactions displayed the same pattern: a fee of 30 sat/vB and no change output. A repetitive on‑chain signature that, according to analysts, could identify the perpetrator, although the pattern itself is not proof of malicious activity and might appear in normal legitimate transactions.

The Flaw: From Hardware Generator to Software PRNG

The flaw dates back to March 2021. That year, an integration error in the Coldcard firmware began routing seed generation away from the true hardware random number generator (TRNG) on the STM32 chip, and instead toward a deterministic software PRNG called Yasmarang. The MICROPY_HW_ENABLE_RNG macro was set to zero, but the libngu library only checked for its existence, not its value. The result: the software fallback always kicked in.

The effective entropy thus collapses to around 40 bits on Mk3 models and 72 bits on Mk4, Mk5, and Q—far from the expected 128 bits for a 12‑word BIP‑39 seed. Anyone who can determine the device identifier, the timer state, and the history of generator calls can reproduce the seed offline and steal funds, without any physical access.

Block, the security team that analyzed the bug, set conditional upper bounds of 2^40.7 and 2^73.3, though noting that the latter does not equate to 73 bits of cryptographic security.

Affected Devices and Required Actions

All seeds created with the following firmware versions are vulnerable:

  • Mk2 and Mk3: from 4.0.0 to 4.1.9 (fixed from 4.2.0);
  • Mk4 and Mk5: versions earlier than 5.6.0;
  • Q: versions earlier than 1.5.0Q;
  • Edge builds: earlier than 6.6.0X (Mk4/5) and 6.6.0QX (Q).

TAPSIGNER, OPENDIME, and SATSCARD use separate codebases and are not affected.

Coinkite released emergency firmware for all models on July 31. The update does not fix seeds already generated. Anyone holding bitcoin on a seed created with vulnerable firmware must take two steps: generate a new seed on an updated device and transfer all funds to it immediately. Restoring the old seed on a new or updated wallet is useless: the weakness lies in the words generated at the time.

A seed created with at least 50 fair, independent, and private dice rolls is not affected by the bug. If the number or privacy of the rolls is uncertain, migration is still recommended. A strong BIP‑39 passphrase creates a separate wallet, but Coinkite still recommends replacing the underlying seed. Multisig schemes protect only when the quorum is not composed entirely of vulnerable devices.

The Background: From “Ill Bloom” Research to an Anonymous Blockchain Signature

The disclosure of the flaw comes just weeks after Coinspect’s “Ill Bloom” research (published in early July), which had already highlighted another weak PRNG bug in old software wallets. In that case, losses recorded since May on Bitcoin, Ethereum, Tron, Rootstock, and Polygon exceeded $5 million.

No attribution has been made for the July 30 theft. Galaxy isolated the recurring signature, but there is still no public proof of reconstructing a single seed associated with one of the drained addresses. The attacker’s identity remains unknown, while Coldcard users rush to check the creation date of their seed and, if in doubt, empty their wallets before someone else does.

Read next

Sources

This article is an original reworking based on the sources below.

Back to home

Latest Cybersecurity News

All cybersecurity news →