Grafa
Coldcard exploit exposes $114M wallet risk
Image for illustrative purposes only. Not a real photo.

Coldcard exploit exposes $114M wallet risk

Share
  • A Coldcard firmware flaw has contributed to nearly US$114 million in reported Bitcoin losses.
  • The flaw weakened seed phrase randomness, making some private keys easier for attackers to guess.
  • The incident shows air-gapped wallets can reduce online attacks but cannot remove firmware and hardware risks.

A Coldcard firmware flaw has contributed to nearly US$114 million in reported Bitcoin (CRYPTO:BTC) losses despite its offline design.

Coinkite disclosed that a March 2021 firmware build error reduced the randomness used to generate some Coldcard seed phrases.

The weaker randomness made affected private keys easier to guess, with attackers potentially using AI to speed up the process.

Galaxy Research tracked losses rising from about US$88 million to nearly US$114 million within days.

Air-gapped wallets stay disconnected from Wi-Fi, Bluetooth and NFC, reducing exposure to malware and other remote attacks.

The Coldcard incident shows wallet security also depends on firmware, hardware, random number generation and secure development practices.

At the time of reporting, Bitcoin price was $63,711.20.

Frequently asked questions

Grafa is not a financial advisor. You should seek independent, legal, financial, taxation or other advice that relate to your unique circumstances.

Grafa is not liable for any loss caused, whether due to negligence or otherwise arising from the use of or reliance on the information provided directly or indirectly, by use of this platform.