Block's investigation traced the Coldcard attacker to a blockchain services provider, exposing a firmware flaw that drained $38.3 million in Bitcoin.
Block's investigation traced the Coldcard attacker to a blockchain services provider, exposing a firmware flaw that drained $38.3 million in Bitcoin.

Block's investigation traced the Coldcard attacker to a blockchain services provider, exposing a firmware flaw that drained $38.3 million in Bitcoin.
Block traced the Coldcard attacker to a blockchain services provider after 594.48 BTC worth $38.3 million was drained from roughly 500 wallets in 25 minutes.
"At a glance, this looks like there was flawed entropy in wallet generation somewhere along the way," Rob Hamilton, CEO and co-founder at AnchorWatch, said.
The sweep moved 1,324 unspent transaction outputs across 500 transactions within a three-block window between 01:31 and 01:56 UTC on Friday. About 562 BTC was later consolidated into a single address. All drained wallets used single-signature setups and held more than 0.15 BTC, with coins dating from 2021 through 2026.
The vulnerability stems from a firmware build setting that caused Coldcard devices to bypass their hardware random-number generator, according to Block's Bitcoin engineering and security teams. Coinkite said the effective search space for an Mk3 seed was about 40 bits against the 128 bits a seed is meant to have.
A supporting software library checked only whether the setting existed, not whether it was enabled, so the device relied on a software substitute seeded with the chip's serial number and internal clock registers — inputs that are not secret. An attacker able to reconstruct those inputs could reduce the number of possible wallet seeds enough to identify vulnerable addresses.
The issue traces to code dated March 1, 2021, introduced in firmware 4.0.1 for the Mk3. Exposure depends on the firmware running when the wallet seed was created, not when the device was purchased or whether the seed was later imported into another wallet. Moving a vulnerable seed to a Trezor, Blockstream, Foundation or Tangem device does not create new private keys — funds remain controlled by the original compromised seed.
Extra entropy from secure elements on the Mk4, Q and Mk5 lifts their effective search space to roughly 72 bits, which Coinkite said materially improves the position without reaching the target. Tapsigner, Opendime and Satscard use different code and are unaffected.
Coinkite has shipped emergency hotfixes: version 5.6.0 for the Mk4 and Mk5, and 1.5.0Q for the Q. Updating does not repair a seed already created on affected firmware. Owners need a new seed generated on patched hardware, and the company recommends a strong BIP-39 passphrase, at least 99 dice rolls, or both. Mk3 owners, whose model is out of support, are pointed to a separate migration path.
Kevin Loaec, CEO at Wizardsardine, said his current hypothesis is that a low-entropy random-number generator produced wallet seeds with insufficient randomness, and that an attacker may have used an AI-generated script to brute-force affected wallets. Coinkite said it has to assume "someone used AI to review previous versions of our firmware" to uncover the flaw, noting that its own AI-assisted review weeks earlier found nothing.
The incident shows the need for rigorous firmware testing and swift vulnerability disclosures. Block's hardware lead Max Guise urged anyone exposed to move funds as soon as they safely can. Bitcoin traded above $64,000 during early Asian hours, suggesting the theft had little immediate effect on the wider market.
This article is for informational purposes only and does not constitute investment advice.