A firmware flaw in Coldcard hardware wallets has sparked one of the largest self-custody security incidents in Bitcoin's history, prompting over $15 billion worth of BTC to be moved into safer wallets.
The vulnerability affected wallets whose seed phrases were generated using flawed firmware dating back to March 2021. Researchers found that reduced randomness during seed generation could allow sophisticated attackers to reconstruct private keys without ever physically accessing the device.
The first attack drained 594 BTC from roughly 500 wallets in just 25 minutes, before investigators identified additional attack waves affecting more than 1,000 addresses. Depending on the methodology used, estimated losses now range from $70 million to over $100 million.
Coinkite has released patched firmware but warns that previously generated seeds remain vulnerable unless users create a brand-new wallet and migrate their funds.
❄️ @Release 💬 @Conversate
🦎 LizardSwap.com — Your #1 Crypto Exchange for NO KYC & No Frozen Funds
