HackRead

COLDCARD Seed Generation Flaw Linked to Nearly $89 Million Bitcoin Theft


A firmware error that weakened wallet seed generation in several COLDCARD hardware wallets has been linked to three suspected Bitcoin thefts involving 1,367.05 BTC. Galaxy Research, the research division of digital assets company Galaxy, valued the observed losses at about $88.6 million.

The initial theft occurred on July 30, when 1,082.65 BTC was removed from 1,196 addresses within 41 minutes. According to Galaxy Research’s blockchain analysis on X, the transactions shared identical fees and lacked change outputs, indicating that one operator may have conducted the sweep.

Two later suspected attacks brought the observed total to 4,585 drained addresses. The third involved 207.7294 BTC taken from 1,912 addresses, with the attacker using separate destination addresses and different transaction formats that made the activity harder to group.

Galaxy has cautioned that its findings come from Bitcoin blockchain data and the unspent transaction output set. The company has not confirmed that every affected address was generated by vulnerable COLDCARD firmware, or that the same attacker conducted all three attacks.

It is also worth noting that no public investigation has reproduced a victim’s seed and matched it to one of the drained addresses. The reported connection between the firmware flaw and the thefts is supported by blockchain patterns and technical analysis, but it has not been conclusively proven.

For a hardware wallet, the seed is the secret value from which its recovery phrase, private keys and Bitcoin addresses are derived. If that value is created with weak randomness, an attacker may be able to generate candidate seeds offline and compare their addresses with records on the public blockchain.

Block’s Bitcoin Engineering and Security analysis traced the error to firmware changes introduced in 2021. Seed generation was meant to use COLDCARD’s hardware random number generator, but an integration mistake directed it to a deterministic software fallback included with MicroPython.

The faulty check only tested whether a configuration setting existed, not whether it was enabled. Because the setting was defined with a value of zero, the build passed its check while using the software generator, which depended heavily on device identifiers and timing information.

Under Coinkite’s current estimates, affected Mk2 and Mk3 seeds may have about 40 bits of effective entropy. Additional randomness included on the Mk4, Mk5, and Q increased their estimate to about 72 bits, still below the intended 128-bit security level.

According to Coinkite’s security advisory, affected seeds include those generated on Mk2 and Mk3 firmware versions 4.0.1 through 4.1.9. Mk4 and Mk5 seeds created before standard firmware 5.6.0 or Edge 6.6.0X are also covered, along with Q seeds created before standard 1.5.0Q or Edge 6.6.0QX.

Installing fixed firmware prevents the same error during future seed generation, but it does not repair an existing seed. Restoring the old recovery phrase on updated firmware or importing it into another wallet carries the same weakness with it.

Coinkite advises affected owners to install the correct fixed version, generate a new seed, verify its backup and receiving address, send a small test payment, and then transfer the remaining balance. Coinkite says users who supplied at least 50 fair, private dice rolls during seed creation are not exposed to this flaw alone.

A strong and unique BIP-39 passphrase adds another barrier, but Coinkite still recommends migration. The company’s technical explanation remains preliminary while its investigation continues. TAPSIGNER, OPENDIME, and SATSCARD are not affected because they use different code.

(Photo by Mariia Shalabaieva on Unsplash)





Source link