A significant security breach has been linked to Coldcard hardware wallets, resulting in an $88.6 million Bitcoin theft. The attack exploited a vulnerability in the random number generator, allowing attackers to deduce private keys without needing direct access to the devices.
Discovery of the Security Breach
Galaxy Research, a digital asset analysis firm, uncovered suspicious activity on July 30. During a swift 41-minute operation, the attackers managed to extract approximately 1,082.65 BTC, valued at $70.2 million, from 1,196 different addresses.
By August 1, further suspicious transactions were identified, increasing the total amount stolen to 1,367.05 BTC, equating to around $88.6 million, across 4,585 addresses. The transaction patterns indicated a single operator for the first two waves, while the third exhibited variations, suggesting the potential involvement of a different attacker or modified tools.
Technical Details of the Exploit
This attack diverges from typical hardware wallet breaches, which often involve phishing or physical access. Instead, it targeted the wallet creation process. The core issue was traced by Block’s Bitcoin Engineering and Security teams to a code modification on March 1, 2021, which disabled the STM32 hardware random number generator in Coldcard’s production setup.
A flaw in the libngu library caused the system to default to a less secure software generator, Yasmarang, seeded from the device’s UID and timer state. This compromised the randomness of seed generation, allowing attackers to recreate potential seed values offline.
Impact and Recommendations
Coinkite, the manufacturer, revealed that the entropy of affected devices dropped significantly, to approximately 40 bits for Mk3 models and around 72 bits for Mk4, Mk5, and Q models, compared to the standard 128 bits expected from a BIP-39 recovery phrase. This decreased randomness enabled attackers to identify wallets holding Bitcoin by cross-referencing with blockchain data.
Devices impacted include Mk2 and Mk3 models with firmware versions 4.0.1 to 4.1.9, and Mk4, Mk5, and Q models with versions before 5.6.0, 5.6.0, and 1.5.0Q, respectively. Coinkite has advised users to update their firmware and generate new seeds.
Emergency firmware updates were released on July 31, but users must generate new seeds and migrate their funds to secure their assets. Experts also recommend using multi-signature setups across different manufacturers to mitigate risks from isolated vendor vulnerabilities.
As the investigation continues, this incident underscores the importance of robust security practices in safeguarding digital assets.
