Massive BTC Drain Sparks Security Concerns After Wallet Weakness Exploited

A critical flaw in a hardware wallet’s randomness system allowed attackers to predict wallet seeds that were supposed to be impossible to guess, leading to the theft of approximately $38 million in Bitcoin.

Around 594 BTC, worth roughly $38 million, was drained from nearly 500 separate wallets within a 25-minute period between 01:31 and 01:56 UTC on Friday. The incident was traced to a vulnerability in the way Coldcard hardware wallets generated cryptographic keys.

The attacker moved 1,324 Bitcoin outputs through 500 transactions spread across just three blocks. After the initial withdrawals, about 562 BTC was consolidated into a single address, where the stolen funds remain untouched.

All compromised wallets were single-signature wallets with balances exceeding 0.15 BTC. Many had been inactive for years, and the affected Bitcoin came from transactions dating between 2021 and 2026, closely matching the period when the security issue was present.

Coldcard, developed by Canadian firm Coinkite, is a hardware wallet that keeps Bitcoin private keys stored offline, protecting them from internet-connected threats. The product family includes several generations, including Mk2, Mk3, Mk4, Q, and Mk5 models released over time.

The vulnerability was determined by the firmware version running when the wallet was initially created, rather than when the physical device was purchased.

Bitcoin wallet seed phrases are designed to rely on extremely strong randomness, creating such a large range of possible combinations that brute-force attacks are considered practically impossible.

However, Coldcard’s firmware introduced a weakness that reduced this protection. Research from Block’s Bitcoin engineering and security teams found that a build configuration caused the device to skip its hardware random number generator. A supporting library only verified that the configuration existed, not whether it was properly activated.

This caused key generation to rely on a weaker software-based fallback that used the device’s serial number and clock register values to create randomness.

Those sources were not confidential. The serial number is fixed manufacturing information, while clock data is a timing variable that attackers could estimate or reproduce using similar hardware. Block traced the issue to a code change made on March 1, 2021, which was included in firmware version 4.0.0 released that month.

Coinkite warned users who generated wallet seeds on Mk3 devices running affected firmware versions and said its early assessment showed that Mk4, Q, and Mk5 devices were not impacted.

Block disclosed the findings to Coinkite, which confirmed the issue. Both companies described their reviews as preliminary, while Block said it released the information before completing full exploit validation because active exploitation was already underway.

The security issue was not limited to wallet seed phrases. The same flawed random generation process also affected Coldcard paper wallet private keys, seed-splitting masks, device cloning keys, and Key Teleport transfers.

Despite the large-scale Bitcoin theft, the broader market remained relatively stable. Bitcoin traded above $64,000 during early Asian trading hours, with the incident appearing to have little immediate effect on overall market sentiment.

  • Related Posts

    Coldcard Flaw Sparks Panic Among Bitcoin Veterans as Wallet Security Comes Under Scrutiny

    The Bank of Japan kept its key policy rate unchanged at 1%, while Governor Kazuo Ueda’s hawkish remarks had limited influence on markets as traders had already accounted for the…

    Continue reading
    BTC Struggles for Momentum While Kospi’s 17% Rally Leaves Crypto Behind

    Samsung and SK Hynix shares jumped more than 23% each, but Bitcoin barely reacted, moving only slightly over the past 24 hours as most major cryptocurrencies remained in the red…

    Continue reading