Coldcard Hardware Wallet Flaw Linked to $70 Million Bitcoin Theft in 41 Minutes

Summary

An attacker exploited a firmware flaw in Coldcard hardware wallets to steal approximately $70.2 million worth of Bitcoin in just 41 minutes. The flaw, identified as a March 2021 firmware integration error, affected seed generation.

IFF Assessment

FOE

The identified vulnerability allowed for a massive theft of cryptocurrency, representing a significant loss for defenders of digital assets.

Severity

9.0 Critical (AI Estimated)

The vulnerability allowed for the theft of a large amount of cryptocurrency with a likely low attack complexity and high impact, suggesting a critical severity.

Defender Context

This incident highlights the critical importance of rigorous security auditing and timely patching for hardware wallets, which are trusted to secure significant digital assets. Defenders should be aware of potential supply chain vulnerabilities and the impact of flawed random number generation on cryptographic security.

Read Full Story →