Coldcard Firmware Flaw Drains 1,778 BTC, About $112M, From Over 5,000 Addresses

AI مارکیٹ کا خلاصہ
A Coldcard firmware vulnerability tied to flawed seed generation allegedly enabled coordinated attackers to drain ~1,778 BTC (~$112M) from thousands of addresses, highlighting systemic self-custody operational risk. Even patched firmware does not secure wallets created under vulnerable versions, forcing seed regeneration and fund migration. The incident can pressure market confidence in hardware wallets, elevate security scrutiny across wallet vendors, and temporarily increase on-chain movement as affected users rotate keys.
اثر کی سطح
● ہائی
متاثرہ اثاثے
BTC/USDT-0.68%
AI تجزیاتی سمجھ · BTC/USDTAI تجزیاتی سمجھ
▼ Bearish
ابھی ٹریڈ کریں
⚠️ AI سے تیار کردہ تجزیاتی سمجھ خبروں کے مواد پر مبنی ہے اور صرف معلوماتی مقاصد کے لیے فراہم کی گئی ہے۔ یہ سرمایہ کاری کا مشورہ نہیں ہے اور نہ ہی BingX کے خیالات کی نمائندگی کرتی ہے۔ سرمایہ کاری میں رسک شامل ہے۔ براہ کرم ذمہ داری سے ٹریڈ کریں۔
Coinkite, the maker of the Coldcard hardware wallet, is dealing with what could become the largest recorded breach involving a hardware wallet. Attackers exploited a vulnerability in Coldcard firmware to steal more than 1,778 Bitcoin—about $112 million at current prices—from over 5,000 addresses. The theft began on July 30, 2026. In the first 41 minutes, the attackers swept more than 1,000 BTC from over 1,000 addresses. By mid-August 2026, roughly 1,531 BTC was still sitting untouched in wallets controlled by the attackers. At the center of the incident is a firmware defect introduced in Coinkite's March 2021 release, version 4.0.1. That update altered the seed phrase generation process—the step where the device creates the master key controlling all funds. Instead of drawing randomness from the device's dedicated hardware random number generator, the affected code used a software-based pseudorandom number generator. That distinction is critical: software PRNG output is materially more predictable than hardware entropy, and predictability in cryptographic randomness can undermine the security of generated keys. Galaxy Research reports that a developer raised a related issue with Coinkite as early as May 2025. The vulnerability remained unpatched long enough for attackers to build tooling and execute the exploit at scale, impacting multiple Coldcard models, including Mk2, Mk3, Mk4, Q, and Mk5. Galaxy Research said at least a dozen distinct attackers participated, all leveraging the same core weakness. Coinkite published a security advisory on July 30, the day the attacks began. Patched firmware for affected models was available by July 31, and CEO Rodolfo Novak issued a public apology. For Coldcard owners, the key point is that updating firmware is not sufficient on its own. Because the flaw affects seed generation at the moment a wallet is created, any seed phrase generated while the device ran a vulnerable firmware version should be treated as compromised, regardless of what firmware is installed now. Coinkite is advising impacted users to generate entirely new seed phrases using patched firmware and move all funds to newly created wallets immediately. The incident also adds friction to the industry's long-running argument that self-custody is inherently safer than relying on centralized exchanges. A firmware-level compromise places the user as the final line of defense—and in practice, many users may not learn anything is wrong until funds are already gone. A defect introduced in 2021, flagged in 2025, and exploited in 2026 is an uncomfortable timeline for a sector that markets hardware wallets as the security gold standard. For wallet competitors, the questions from customers and security researchers are likely to be direct: how do you verify that RNG implementations actually use hardware entropy, and how quickly can you ship a verified patch when they do not.