🚨 The Silent Heist!
How a 2021 code flaw in
#Coldcard enabled the theft of $38 million in
#bitcoin in just 25 minutes
In a surgical operation that has shaken trust in “cold storage,” cyber pirates managed to drain approximately 594
#bitcoins in a tight window of only 25 minutes. What’s most alarming isn’t the speed of the theft, but the attack vector: a silent vulnerability lurking inside the firmware of the well-known Coldcard hardware wallets for over five years.
The Heist Execution: Between 01:31 and 01:56 UTC on Friday, the attackers emptied around 500 wallets (all single-signature and with more than 0.15 BTC). After moving the funds in a burst of transactions, they consolidated 562
#BTC into a single address that remains inactive. Many of the affected wallets had gone years without any movement.
The Fatal Flaw (“RNG Gate”): Investigations by Block’s security team revealed a catastrophic error. Starting with firmware 4.0.0 (March 2021), a faulty configuration disabled the device’s hardware random number generator.
Predictable Seeds: Instead of generating mathematically impossible-to-guess seed phrases, the device used a basic software routine that relied on the chip’s serial number and the system clock. Since this data was public or easy to measure, attackers could deduce the master keys without physically touching the devices.
Models at Risk: Coinkite, the Canadian manufacturer, issued a red alert for users who generated their seed on an Mk3 model using version 4.0.1 or later. The risk depends on the wallet creation date (2021–2026), not on when the device was purchased. Preliminary analysis indicates the newer models (Mk4, Q, and Mk5) are not affected.
#Hack $BTC $ETH $SOL