ShellCodeX Intelligence Brief
CRITICAL
Vulnerabilities
Coldcard firmware flaw links to $70M Bitcoin drain in 41 minutes
Source headline: Coldcard Hardware Wallet Flaw Linked to $70 Million Bitcoin Theft in 41 Minutes
Threat level
Critical
Signal strength
90/100
Source confidence
1 source
Published
2 hours ago
Intelligence Summary
Galaxy Research says an attacker drained many Coldcard-related Bitcoin addresses in 41 minutes. The theft totaled 1,082.65 BTC, worth about $70.2 million at the time. The incident was linked to a firmware integration error that altered seed generation. Instead of using proper randomness, the wallet routed generation to a deterministic software PRNG. Coldcard users and administrators should assume private seed generation integrity is at risk and ensure they are on fixed firmware.
Recommended Action
Prioritize immediate review, validate exposure, and patch or mitigate affected systems.
Topics
Original reporting
The Hacker News
Coldcard Hardware Wallet Flaw Linked to $70 Million Bitcoin Theft in 41 Minutes
Open original source