ShellCodeX
Tools • Events • News • Insights
ShellCodeX Intelligence Brief
CRITICAL Vulnerabilities

Coldcard firmware flaw links to $70M Bitcoin drain in 41 minutes

Source headline: Coldcard Hardware Wallet Flaw Linked to $70 Million Bitcoin Theft in 41 Minutes

Threat level Critical
Signal strength 90/100
Source confidence 1 source
Published 2 hours ago

Intelligence Summary

Galaxy Research says an attacker drained many Coldcard-related Bitcoin addresses in 41 minutes. The theft totaled 1,082.65 BTC, worth about $70.2 million at the time. The incident was linked to a firmware integration error that altered seed generation. Instead of using proper randomness, the wallet routed generation to a deterministic software PRNG. Coldcard users and administrators should assume private seed generation integrity is at risk and ensure they are on fixed firmware.

Recommended Action

Prioritize immediate review, validate exposure, and patch or mitigate affected systems.

Topics

#financial-theft #bitcoin #coldcard #firmware-flaw #hardware-wallet #prng #seed-generation
Original reporting The Hacker News Coldcard Hardware Wallet Flaw Linked to $70 Million Bitcoin Theft in 41 Minutes
Open original source