importantSYS.SOURCE: The Hacker News• 2026-08-01T22:47:22+05:30
Coldcard Hardware Wallet Firmware Vulnerability Enables $70M Bitcoin Theft in 41 Minutes
A firmware vulnerability in Coldcard hardware wallets allowed an attacker to steal $70 million in Bitcoin by exploiting a deterministic pseudorandom number generator (PRNG) flaw. The flaw, stemming from a 2021 configuration error, reduced entropy in seed generation, enabling offline seed reconstruction and address drainage.
An attacker drained 1,196 Bitcoin addresses in 41 minutes on July 30, taking 1,082.65 BTC worth about $70.2 million at the time. Galaxy Research mapped the sweep and tied it to a firmware flaw in Coldcard, the Bitcoin-only hardware wallet made by Canadian firm Coinkite.
A March 2021 firmware integration error routed seed generation to a deterministic software pseudorandom number generator (PRNG
*** END OF TRANSMISSION ***