
Coldcard exploit exposes $114M wallet risk
- A Coldcard firmware flaw has contributed to nearly US$114 million in reported Bitcoin losses.
- The flaw weakened seed phrase randomness, making some private keys easier for attackers to guess.
- The incident shows air-gapped wallets can reduce online attacks but cannot remove firmware and hardware risks.
A Coldcard firmware flaw has contributed to nearly US$114 million in reported Bitcoin (CRYPTO:BTC) losses despite its offline design.
Coinkite disclosed that a March 2021 firmware build error reduced the randomness used to generate some Coldcard seed phrases.
The weaker randomness made affected private keys easier to guess, with attackers potentially using AI to speed up the process.
Galaxy Research tracked losses rising from about US$88 million to nearly US$114 million within days.
Air-gapped wallets stay disconnected from Wi-Fi, Bluetooth and NFC, reducing exposure to malware and other remote attacks.
The Coldcard incident shows wallet security also depends on firmware, hardware, random number generation and secure development practices.
At the time of reporting, Bitcoin price was $63,711.20.