Crypto
Home›Crypto›Market Structure›Coldcard firmware flaw drained nearly $114 million in…
Coldcard firmware flaw drained nearly $114 million in bitcoin
The seed randomness bug was introduced via a March 2021 code change after a 2020 licensing shift, and the first sweeps emptied roughly 500 wallets in 25 minutes.
Attackers have drained nearly $114 million in bitcoin from more than 709 addresses by exploiting a Coldcard firmware flaw that generated wallet seeds with only a fraction of the promised randomness, according to an analysis by CoinDesk. The first sweep emptied roughly 500 wallets in 25 minutes. The vulnerability entered the codebase in March 2021 and was visible in public open-source view for more than five years, the article says.
CoinDesk links the timeline of the bug to a licensing and rewrite sequence. It notes that in 2020 Coldcard firmware used a GPL open-source license, and that after a competitor announcement that used GPL code, Coldcard later adopted a Commons Clause license, after which a sweeping rewrite followed.
The analysis argues the core issue was not only the code change but also failures in verification. It cites disclosures in August 2020 by researchers from Shift Crypto and Nunchuk about a multisig verification flaw, and describes later pushback around research into reproducing older builds in 2023, alongside the March 2021 commit that both stripped out remaining GPL code and broke seed generation.
Latest closeBitcoin $64,381.79 ▲2.5%