Coldcard Vulnerability Exposes 38 Million in Bitcoin: Hardware Wallet Crisis Deepens
A critical flaw in Coldcard hardware wallets allowed attackers to drain over 500 addresses of 594.48 BTC in a single automated exploit. Security researcher Block Security identified the vulnerability affecting multiple device models.
A Critical Entropy Failure
The cryptocurrency hardware wallet industry faces a confidence crisis following the discovery of a severe vulnerability in Coldcard devices. Security researchers at Block Security uncovered a fundamental flaw in how the wallets generate seed phrases—the cryptographic keys that control user funds. The weakness manifested differently across device generations: older models contained a firmware bug that deactivated the hardware-based random number generator, forcing fallback to a predictable software alternative, while newer versions truncated critical entropy data. Both scenarios dramatically reduced the number of theoretically possible seed phrase combinations, enabling attackers to systematically crack them in minutes using ordinary computers.
The exploitation resulted in the theft of 594.48 Bitcoin, valued at approximately $38.3 million, from more than 500 individual addresses. Hackers consolidated the stolen assets into a single wallet in what appears to be an automated assault leveraging the predictable entropy. Nearly all Coldcard models proved vulnerable to the attack, including the Mk2, Mk3, Mk4, Q, and Mk5 versions.
Industry Skepticism and the Todd Perspective
Bitcoin developer Peter Todd, whom an HBO documentary previously identified as a potential creator of Bitcoin, seized on the incident to validate his longstanding doubts about commercial hardware wallet products. Todd argued that the ecosystem places excessive faith in closed-source firmware running on chips that could harbor supply-chain vulnerabilities, all with minimal independent code review. He advocated instead for transparent, deterministic key generation methods—ones users can verify and audit themselves—and highlighted alternative approaches including physical entropy generation using standard playing cards and previously proposed button-based random number systems.
Todd’s critique extends beyond this single incident: hardware wallets offer convenience at the cost of security assumptions most users cannot independently validate. The Coldcard case exemplifies this trade-off’s consequences.
Urgent Remediation Required
Users holding Bitcoin on affected Coldcard models face an uncomfortable reality: migrating compromised seed phrases to new hardware provides no protection, since the flawed entropy persists from the original generation moment. The only secure path forward involves creating entirely new seed phrases on verified hardware and transferring all assets to fresh addresses. Notably, users who added a BIP-39 passphrase during the initial wallet setup retain partial protection, as this additional layer complicates brute-force attacks even against predictable seed phrases.
Multisignature arrangements present an additional complication. If all signing keys for a multisig scheme were generated using the vulnerable Coldcard firmware, attackers can potentially compromise individual keys sequentially, potentially unraveling the security architecture that multisig is designed to provide. The incident underscores how deeply seed-generation vulnerabilities can penetrate wallet security structures.
For cryptocurrency holders across all protocols, the Coldcard incident represents a sobering reminder that hardware solutions demand rigorous auditing and transparency standards. This matters for XRP and the entire cryptocurrency market, as confidence in infrastructure security directly impacts user adoption and asset safety.
Source: Block Security, via U.Today. Not financial advice.