Home/News/Major bitcoin wallet flaw drains 594 BTC in 25-minute sweep
BTCUSD

Major bitcoin wallet flaw drains 594 BTC in 25-minute sweep

CoinDeskPublished on last week

A hardware wallet randomness bug turned “impossible to guess” seeds into guessable ones, and $38 million is already gone.

Major bitcoin wallet flaw drains 594 BTC in 25-minute sweep

A hardware wallet randomness bug turned “impossible to guess” seeds into guessable ones, and $38 million is already gone.

An attacker exploited a flaw in how some Coldcard hardware wallets generated keys to steal roughly 594 bitcoin, worth about $38 million, from around 500 single-signature wallets in under 30 minutes. The vulnerability, introduced in Coldcard firmware 4.0.0 in March 2021, caused devices to skip their hardware randomness generator and fall back to predictable software-based key generation seeded by nonsecret chip data. Coinkite has warned users who created seeds on Mk3 devices running firmware 4.0.1 or later, while stressing that Mk4, Q and Mk5 appear unaffected so far, and the theft has had little visible impact on bitcoin’s market price.

Roughly 594 bitcoin, worth about $38 million, was swept out of around 500 separate wallets between 01:31 and 01:56 UTC on Friday in an attack traced to a flaw in how Coldcard hardware wallets generated their keys.

The theft moved 1,324 chunks of bitcoin across 500 transactions inside a three-block window, with 562 BTC then consolidated into a single address that has not moved.

Every drained wallet was single-signature and each held more than 0.15 BTC. Many had been dormant for years and the coins spanned 2021 to 2026, matching the flaw's age almost exactly.

Coldcard is a hardware wallet built by Canadian firm Coinkite, a small standalone device that stores bitcoin keys offline, away from internet-connected computers. Mk2, Mk3, Mk4, Q and Mk5 are successive generations of that product, released over several years the way a phone maker ships numbered models.

Exposure depends on the firmware the device was running at the moment the wallet was first created, not on when the hardware was bought.

A wallet's seed, the secret phrase controlling the funds, is meant to be drawn at random from a pool so vast that guessing is hopeless.

Coldcard's firmware was not doing that. According to a report published by Block's Bitcoin engineering and security teams, a build setting told the device to skip its own hardware randomness generator, and a check in a supporting library tested only whether that setting existed rather than whether it was switched on.

Key generation quietly fell through to a basic software substitute seeded from the chip's serial number and clock registers.

None of those are secrets. The serial number is fixed factory metadata, and the clock values are timing state an attacker can narrow down or measure on a device of their own. Block traced the change to a commit dated March 1, 2021, shipped in firmware 4.0.0 that month.

As such, Coinkite warned users who generated a seed on an Mk3 running version 4.0.1 or later, and said "Mk4, Q and Mk5 are not affected based on our early analysis."

Block said it disclosed its findings to Coinkite, whose team acknowledged them. Both companies describe their analyses as preliminary, and Block said it published without full testing to confirm exploitability because exploitation was already under way.

The exposure runs past wallet seeds. The same generator produced Coldcard's paper wallet private keys, where the output becomes the key directly with no further derivation, along with seed-splitting masks, device cloning keys and Key Teleport transfers.

Bitcon traded above $64,000 in early Asian hours, with widespread drain appearing to have little impact on the market.

1Strategy books $8.2 billion Q2 loss on bitcoin price decline 9 hours ago 2Coinbase sinks 5% after missing second quarter revenue estimates9 hours ago 3Global banks test tokenized money for cross-border payments in $1 million BIS pilot12 hours ago 4Ondo Finance weighs acquisition worth up to $500 million13 hours ago 5Crypto for Advisors: Is the Clarity Act dead?14 hours ago 6CME's Duffy warns an overlooked tax risk looms over U.S. perpetual futures15 hours ago 7The economics behind Aave proposal to ditch 6 chains that earn loose change in revenue15 hours ago 8JPMorgan says fading Clarity Act odds weigh on crypto outlook15 hours ago 9Institutional crypto trading hits a record 72% as Wall Street calms crypto's wild swings15 hours ago 10Ethereum enters its second decade after a year of upheaval at the foundation15 hours ago

Anvil: The Missing Collateral Layer

Anvil: The Missing Collateral Layer

Anvil is a shared on-chain collateral layer built on a programmable letter of credit: reserve assets as a guarantee -no loan, no interest, keep custody & yield.

Anvil is a shared on-chain collateral layer built on a programmable letter of credit: reserve assets as a guarantee -no loan, no interest, keep custody & yield.

Why it matters:

Anvil is a shared on-chain collateral layer built on a programmable letter of credit: reserve assets as a guarantee -no loan, no interest, keep custody & yield.

The economics behind Aave proposal to ditch 6 chains that earn loose change in revenue

Ethereum enters its second decade after a year of upheaval at the foundation

Live updates: Bitcoin holds above $64,000 as Nasdaq surges on AI trade comeback