National
Security Flaw in Coldcard Hardware Wallets Enables Mass Bitcoin Theft
By coindesk|
1 min read
A firmware vulnerability in Coldcard hardware wallets allowed attackers to recreate private keys offline, leading to the theft of over 1,000 BTC (worth approximately $70 million) from nearly 1,196 wallets within 41 minutes on July 30. The flaw made seed phrases computationally enumerable, enabling key reconstruction without physical access. Security experts warn additional wallets may still be at risk as users cannot confirm if their seed generation was compromised. The stolen funds remain unspent and are traced to four blockchain addresses.