Article may be outdated

This article is 61 days old. Some details may have changed since publication.

CoinDesk·4 min read·medium

Major bitcoin wallet flaw drains 594 BTC in 25-minute sweep

S
Shaurya Malwa
Major bitcoin wallet flaw drains 594 BTC in 25-minute sweep
✦AI Summary

A critical firmware flaw in Coldcard hardware wallets allowed attackers to predict private keys by bypassing the device's hardware random number generator. This vulnerability, which affected specific models since 2021, resulted in the theft of 594 BTC from dormant, single-signature wallets.

Why it matters

This incident highlights a major security failure in self-custody hardware, demonstrating how a single software misconfiguration can compromise assets previously considered immune to online threats.

✦Dive DeeperCreate a free account to unlock

The theft moved 1,324 chunks of bitcoin across 500 transactions inside a three-block window, with 562 BTC then consolidated into a single address that has not moved.

Every drained wallet was single-signature and each held more than 0.15 BTC. Many had been dormant for years and the coins spanned 2021 to 2026, matching the flaw's age almost exactly.

Coldcard is a hardware wallet built by Canadian firm Coinkite, a small standalone device that stores bitcoin keys offline, away from internet-connected computers. Mk2, Mk3, Mk4, Q and Mk5 are successive generations of that product, released over several years the way a phone maker ships numbered models.

Exposure depends on the firmware the device was running at the moment the wallet was first created, not on when the hardware was bought.

Continue reading on Headlinne

Create a free account to read the full article.

Read full article →
technologycryptobusiness
✦

Get smarter about the news

Sign up free for a feed built around what you actually care about, Dive Deeper research on any story, and the full text of every article.

Create free account

Already have an account? Sign in