Intelligence
criticalVulnerabilityActive

COLDCARD RNG Integration Error Linked to $88.6M Bitcoin Theft

A random-number-generator integration error in affected COLDCARD firmware is likely linked to the theft of $88.6 million in Bitcoin from 4,585 addresses across three waves. Exposure depends on the firmware used when a wallet seed was created.

S
Sebastion

Affected

COLDCARD Mk2/Mk3 4.0.1–4.1.9COLDCARD Mk4/Mk5 before 5.6.0COLDCARD Q before 1.5.0Q

The issue was an integration error affecting random-number generation during seed creation, not a deliberate weakness or backdoor. The vulnerable ranges are COLDCARD Mk2 and Mk3 firmware 4.0.1 through 4.1.9, Mk4 and Mk5 firmware before 5.6.0, and Q firmware before 1.5.0Q.

Researchers linked the error to the theft of approximately $88.6 million in Bitcoin from 4,585 addresses. The transfers occurred in three waves. The reporting links the thefts to seeds created under the faulty implementation; it does not establish that the weakness was intentional.

Users can assess possible exposure by identifying the firmware version used when their seed was created. Updating firmware prevents new seeds from being generated by an affected version, but does not change an existing seed. Owners of seeds created within an affected range should follow Coinkite's guidance for moving funds using a seed generated on corrected firmware.

TAPSIGNER, OPENDIME and SATSCARD are unaffected. Coinkite also said it destroyed affected devices that were awaiting shipment rather than sending them to customers. Users should consult the vendor advisory for device-specific upgrade and seed-replacement instructions.