Firmware Flaw Enabled $70 Million Bitcoin Drain in 41 Minutes
A deterministic seed generation error in Coldcard hardware wallets allowed an attacker to systematically empty 1,196 addresses last July.
On July 30, an attacker drained 1,082.65 Bitcoin—worth approximately $70.2 million at the time—from 1,196 addresses in a 41-minute window. Galaxy Research traced the sweep to a firmware integration error in Coldcard, a Bitcoin-only hardware wallet manufactured by Canadian firm Coinkite.
The flaw originated in a March 2021 firmware update that inadvertently routed seed generation to a deterministic software pseudorandom number generator (PRNG) rather than the device's hardware entropy source. This meant that wallet seeds, intended to be cryptographically unique, could be predicted or reconstructed by anyone aware of the implementation error. The attacker appears to have identified the pattern and methodically swept affected addresses.
Coldcard markets itself as a security-first device for high-value Bitcoin custody, favored by institutional holders and privacy-focused users. The March 2021 integration error went undetected for more than four years, during which an unknown number of wallets were initialized with compromised seeds. Galaxy Research has not disclosed how many additional wallets may remain vulnerable, nor whether the attacker's sweep was exhaustive.
- 01Coldcard users who initialized devices between March 2021 and the patch date face potential exposure.
- 02Institutional custody providers relying on Coldcard hardware must audit wallet initialization dates.
- 03Hardware wallet vendors face heightened scrutiny over entropy source verification and regression testing.
- 04Bitcoin holders using deterministic wallets should verify seed generation methods and consider migration.
Boston Scientific confirms cyberattack disrupting medical device shipments
The Massachusetts-based medical device manufacturer disclosed the incident in SEC filings Tuesday, warning of operational impact to its supply chain.
US sanctions Iranian nationals after UK power plant intrusion
Treasury action follows disclosure of cyber operation targeting British energy facility, marking coordinated transatlantic response to infrastructure threats.
Supply-chain attack embeds proxy botnet in Android car head units
Legitimate device-update app compromised to spread malware that turns in-vehicle systems into proxy nodes and ad-fraud platforms.