Coldcard Vulnerability Turns “Impossible to Guess” Seeds Into Guessable Ones, Draining 594 BTC

TL;DR
- An attacker drained roughly 594 BTC worth about $38 million from around 500 Coldcard wallets during a coordinated 25-minute sweep early Friday.
- The flaw bypassed hardware randomness and generated seeds from predictable chip data, shrinking the secret space meant to make private keys effectively unguessable.
- Coinkite issued emergency firmware updates, but existing weak seeds remain vulnerable and must be replaced; the company suspects AI helped uncover the bug at scale.
A vulnerability in Coldcard hardware wallets allowed an attacker to drain roughly 594 BTC, worth about $38 million, from around 500 single-signature wallets in only 25 minutes. The sweep occurred between 01:31 and 01:56 UTC on Friday, moving funds through 500 transactions inside a three-block window with remarkable speed and precision. A device designed to keep keys offline instead produced seeds that could be narrowed down and guessed. Investigators traced 562 BTC into one address that had not moved, while evidence showed many affected wallets had remained dormant for years before the coordinated theft began.
… Continue reading the full article at the original source below.



