$114 Million in Bitcoin Stolen in Coldcard Vulnerability: Update is Not Enough, New Wallet Required
A vulnerability in Coldcard firmware led to attackers stealing approximately $114 million worth of Bitcoin from over 709 addresses, creating a necessity for users to migrate to a new wallet.
According to an opinion piece published on CoinDesk, attackers exploited a firmware bug that caused Coldcard devices to generate wallet seeds with significantly lower randomness than promised. In the first wave of attacks, approximately 500 wallets were drained within 25 minutes.
It was reported that the vulnerability entered Coldcard’s code in March 2021 and remained undetected in the public source code for more than five years. The article emphasized that the fact that open-source code is reviewable by everyone does not provide security on its own; experts are also needed to audit this code.
Coldcard users must switch to a new wallet
Seeds generated on vulnerable firmware versions cannot be fixed by a subsequent firmware update. Therefore, affected users should not settle for just updating their current wallet but must move their assets to a newly generated wallet. The update does not eliminate the risk created by the generation of the faulty seed.
In the CoinDesk article, the fact that the bug went unnoticed for five years was linked to Coldcard’s security culture. The author noted that the vulnerability coincided with the period when cryptographic code was rewritten following a license change in 2020, although they did not confirm that the license decision was the direct cause of the error. The past criticism of independent researchers and the prioritization of reputation over technical verification were also presented as the author’s critique of the security culture. The core message of the news is clear: users should verify their wallets and abandon risky seeds rather than simply trusting the manufacturer.