Coinkite, a Canadian firm known for the Coldcard hardware wallet, revealed a significant flaw in its firmware on July 31, allowing attackers to steal approximately 594 BTC, which is nearly $38 million, from about 500 wallets in rapid succession. The breach occurred in under 30 minutes.
#What Caused This Critical Vulnerability
The issue stemmed from a software update implemented in March 2021, specifically with firmware version 4.0.0. During the integration process of Bitcoin Core’s libsecp256k1 library, a build configuration error replaced the device’s reliable hardware random number generator with a flawed software-based alternative. This fallback relied on predictable, non-secret chip data, which compromised the randomness quality of seed generation on the affected devices.
Coldcard’s Mk3 devices, for instance, had only about 40 bits of effective entropy. This level of entropy is woefully insufficient when compared to the high-security standards expected in the cryptocurrency space. A typical secure wallet requires a keyspace that is astronomically large to protect against attacks; however, the compromised devices offered an opportunity for powerful attackers to brute-force the keys. While the newer Mk4 and Q models performed slightly better with around 72 bits of entropy, this still falls short of the critical 128 or 256 bits deemed necessary by cryptocurrency safety protocols.
#How Was the Flaw Discovered and What Steps Are Being Taken
Coinkite’s statement implied that the vulnerability might have been identified through AI-assisted analysis of its open-source firmware. Interestingly, the company’s own AI-assisted code reviews had overlooked this critical bug. In response to the breach, Coinkite released emergency firmware updates on July 31, specifically version 5.6.0 and above for Mk4 and Mk5 devices, along with version 1.5.0Q and above for the Q model. Users of the compromised firmware must generate completely new seeds using the updated software and transfer their funds as the previous seeds remain vulnerable.
Coinkite is advising affected users to create new seeds and transfer all their Bitcoin to these new wallets. It is also crucial for users to perform test transactions before moving significant amounts to ensure security. The company suggested that strong passphrases could add an extra layer of protection and encouraged users to explore alternative seed generation methods, such as dice rolls, to enhance entropy.
Coinkite confirmed that its other products, including Tapsigner, Opendime, and Satscard, are unaffected by this incident as they operate on different codebases. The breach did not impact other cryptocurrencies or protocols, establishing this as a Bitcoin-specific issue primarily related to wallet-level key generation rather than a broader protocol vulnerability.
#What Does This Mean for Hardware Wallet Users and Investors
The market response to the incident has been relatively calm, indicating that investors consider this an isolated event rather than a systemic risk. However, this situation may prompt increased interest in multi-signature wallet setups. Such configurations, which require approvals from multiple independent devices for fund transfers, render this type of attack ineffective since gaining control over one seed alone is insufficient to access the funds.
Traders and long-term cryptocurrency holders should view this issue as a call to review their security measures seriously. If you are using a Coldcard wallet on any firmware version between 4.0.0 and the patched releases, migrating to a new seed is imperative to ensure the safety of your investments.