Understanding the COLDCARD Hardware Wallet Exploit and Its Implications

By Patricia Miller

2 min read

Block's engineering team identified the cause of the COLDCARD wallet breach, tracing it back to a fifth-year firmware bug.

#What led to the COLDCARD hardware wallet exploit?

The engineering team at Block has successfully traced the source of the recent COLDCARD hardware wallet exploit. The investigation identified the perpetrator as part of a blockchain services provider involved during the theft. This breach, which took place on July 30, resulted in the loss of around 594 BTC, equivalent to nearly $38 million, from approximately 500 wallets within a swift 25-minute period.

#How did a simple firmware bug enable such a significant theft?

The underlying issue stems from a firmware update rolled out in March 2021, specifically version 4.0.0. This update inadvertently disabled the hardware-based random number generator (RNG) in certain COLDCARD devices, instead relying on a less secure software-based alternative. This software fallback utilized non-secret seed values, allowing anyone aware of these vulnerabilities to recreate wallet seeds from the device's metadata. The devices primarily affected included the Mk3 models and some Mk2 units that generated their seeds under the flawed firmware.

This attacker, who appeared to have waited years before exploiting this information, targeted dormant accounts. The short timeframe of the attack indicates advanced planning, suggesting the perpetrator conducted pre-computation of the vulnerable seeds and automated the withdrawal process.

#What actions did Block and Coinkite take?

To address the vulnerability, Block’s engineers collaborated closely with Coinkite, the manufacturer of COLDCARD devices. Together, they tracked the attacker’s on-chain movements to a blockchain services provider. This cooperation facilitated an expedited disclosure of the vulnerability before detailed technical specifics were disclosed to the public.

Coinkite responded promptly by issuing advisories to users of Mk3 and earlier models impacted by the flawed firmware. Their preliminary findings indicated that newer models, including Mk4, Q, and Mk5, were safe from the RNG flaw. Users were strongly advised to create entirely new seeds on unaffected devices and migrate their funds as a precautionary measure.

#What should hardware wallet users know about this incident?

On the day of the breach, Bitcoin was trading above $64,000, with only minimal market repercussions. However, the very firmware update that introduced the flaw—v4.0.0—was initially believed to enhance security, inadvertently putting user wallets at risk. As such, it is essential for hardware wallet users to ensure their devices are updated and secure to prevent falling victim to similar vulnerabilities in the future.

Staying informed about device updates and security measures can safeguard against these types of exploits. It is incumbent upon every user of such technology to regularly verify the integrity of their security settings and exercise caution, especially when dealing with substantial cryptocurrency holdings.

A sharper way to see the markets in just 5 minutes.

Same news, different lens. We cut through the noise and hand you the overlooked ideas and the deeper read the crowd misses. Join 38,000+ investors seeing the markets differently.

I agree to the privacy policy.

Important Notice And Disclaimer

This article does not provide any financial advice and is not a recommendation to deal in any securities or product. Investments may fall in value and an investor may lose some or all of their investment. Past performance is not an indicator of future performance.