Thursday, September 17, 2026

Creating liberating content

Circle opens Arc mainnet...

Circle has scheduled the public launch of Arc for Sept. 16, giving USDC...

ECB opens merchant applications...

The European Central Bank has opened applications for online merchants to join a...

Bitcoin Price Wobbles Before...

Bitcoin’s price swung before settling largely unmoved over a 24-hour period...

Bitcoin miners have amassed...

Bitcoin miners have signed more than $100 billion in AI contracts while generating...

Coldcard Wallet Flaw Exposes Years Of Bitcoin Seeds After $70M In BTC Stolen

The popular Bitcoin hardware wallet Coldcard product, made by Coinkite, is at risk following a $70 million hack.

Coinkite on Thursday admitted that its Coldcard Mk3 model was affected following the hack and advised users to move their funds. Then, on Friday, the company said that users of the later hardware devices Mk4, Mk5, and Q should also take precautions. 

Hackers on Thursday were first able to drain funds from 1,196 Bitcoin addresses because their private keys were not generated using sufficient entropy — or randomness. 

Read More:  Updated Crypto Clarity Act Starts Circulating Days Before Key Vote

Since then, a total of 1,082.65 Bitcoins have disappeared from wallets, according to data from Galaxy Research and engineers at payments company Block. 

While Coinkite has not admitted that the hack is linked to their wallets, the company has said that a wallet seed generation bug in Coldcard products meant the hardware’s true random number generator wasn’t actually being used on certain firmware versions. 

Read More:  Bitcoin Shrugs Off Fed Chair's Inflation Comments

Coinkite and other engineers in the Bitcoin space are still investigating reportedly ongoing drains still happening at the time of writing.

What actually happened 

A firmware bug in Coldcard Mk3 devices (starting with version 4.0.1 in March 2021) caused seed generation to fall back to a weak software PRNG instead of the hardware true random number generator, producing seeds with only ~40 bits of entropy rather than the intended 128.  This made private keys for many single-signature wallets (especially those created without dice rolls or a strong BIP-39 passphrase) predictable enough for attackers to brute-force.

Read More:  Strategy Craters 10%, Hits 2-Year Low As BTC Falls To $59K

A total of 594.5 Bitcoins worth over $35.7 million at today’s prices were moved to a new address from single-signature addresses on Thursday.