The Latest Crypto News
Friday, 25 September 2026 BTC -- / --
🔍

Vulnerability in Coldcard wallet led to theft of $111 million in Bitcoin

Make The Latest Crypto News preferred on Google
A black Coldcard hardware wallet beside a gold Bitcoin coin, with a broken digital padlock icon.
A black Coldcard hardware wallet beside a gold Bitcoin coin, with a broken digital padlock icon.

A serious weakness in the Coldcard hardware wallet’s private key generation has led to the theft of at least 1,719 Bitcoin, currently worth over $111 million. Security company SlowMist is fully reconstructing the attack and explains how thousands of wallets were vulnerable due to a firmware error.

Bitcoin is available at OKX and Bybit.

In short:

  • A configuration error in the Coldcard firmware disabled the hardware random number generator, causing a weak software-based variant to be used.
  • Attackers were then able to guess the private keys of vulnerable wallets using GPU clusters and drain the funds.
  • The stolen Bitcoin was spread across hundreds of addresses in multiple waves, part of which was laundered via Wasabi Wallet and THORChain.

Firmware error as the cause of the attack

SlowMist’s security team is analysing the attack on the basis of Coldcard firmware version Mk3 4.1.9 and reconstructing the entire attack chain. The core of the problem lies in a configuration error in which the MICROPY_HW_ENABLE_RNG setting was set to 0. This silently disabled the hardware random number generator of the STM32 chip, and a weak software-based variant took over: the Yasmarang PRNG, which is not cryptographically secure.

Because of this error, the effective entropy on Mk2 and Mk3 devices was reduced to only about 40 bits, and on Mk4, Mk5 and Q models to around 72 bits. This sounds technical, but the practical consequence is clear: attackers could in practice predict or brute-force the seemingly random numbers used to create a seed.

How the attack worked

The attackers modelled three common usage patterns when starting up a Coldcard, such as a first boot or creating a paper wallet. They then ran GPU clusters to compute candidate keys through a fixed sequence of steps: SHA-256, BIP-39, PBKDF2-HMAC-SHA512, BIP-32 and finally the derivation of the wallet address. These computed addresses were compared against a large set of known Bitcoin addresses to identify and drain vulnerable wallets.

The stolen Bitcoin flowed away in multiple waves. In the first wave, 1,082.6 Bitcoin ended up at a handful of addresses, one of which still contains 398 Bitcoin. The second wave involved 76.1 Bitcoin, the third 207.7 Bitcoin spread across no fewer than 293 addresses, and the fourth wave of 64.9 Bitcoin disappeared via Wasabi Wallet. Part of the remaining funds was converted via THORChain, and 200 Ethereum disappeared through Tornado Cash, both well-known routes used to conceal the origin of stolen crypto.

What affected users should do now

SlowMist advises anyone with an affected Coldcard device to install the patched firmware immediately. After that, it is necessary to create a completely new seed. Users are advised to first send a small amount as a test, confirm that the new address works correctly, and only then transfer the remaining balance.

SlowMist’s full technical analysis is available via Medium. The attack affected more than 5,200 addresses and shows how an apparently minor configuration error in hardware wallet firmware can have far-reaching consequences for end users.

Summarize this article with AI

Not financial advice. The Latest Crypto News provides educational and informational content only. Crypto-assets are highly volatile and you can lose your entire investment. Always do your own research. Read our full disclaimer.

Affiliate disclosure. Some links on this site are affiliate links. If you sign up with a partner through one of them, we may earn a commission at no extra cost to you. This never influences our reporting. See our editorial guidelines.

More Scam News

More news ›