- Coldcard wallet faces scrutiny for failing to address a flaw dating back to 2021, which led to thousands of Bitcoin losses.
- The incident highlights the cold, hard fact that even air-gapped crypto devices are not safe.
Coldcard, a Bitcoin (BTC)-focused hardware wallet, is currently facing public backlash after a long-standing critical flaw has caused users to lose their self-custodied assets. As of Sunday, reported losses have ranged between $38 million and $71 million—with most sources estimating the compromised assets at approximately 1,128.66 BTC. However, actual figures could be worse.
The gravity of the incident has even sparked concerns among industry leaders. Former Binance CEO Changpeng “CZ” Zhao stated that the event underscored the need for crypto users to be vigilant, especially if they have chosen self-custody rather than entrusting their digital assets to third-party entities. He advised them to diversify funds across multiple wallets to avoid a single point of failure.
Then, CZ highlighted that developers simply patching a bug won’t fix previously generated wallets. Their patches also face the challenge of reaching air-gapped devices.
Hence, a wallet stays open to hackers until the owner acts. Despite the issues, CZ noted that he remains a believer in self-custody, but it puts the burden on users.
Meanwhile, Strike CEO Jack Mallers called the exploit “one of the most serious Bitcoin wallet security breaches to date.” He urged people to inform anyone they know who is using a Coldcard hardware wallet about the ongoing situation so they can act on it right away.
Mallers informed the public that Strike is willing to assist affected users, whether or not they are their customers. All they have to do is contact their company’s support team.
“Bitcoiners take care of Bitcoiners,” Mallers reminded the crypto community.
Standout Features of Coldcard
Coinkite launched the Coldcard hardware wallet in 2017. The product stands out among alternatives with its retro-calculator design, complete with a physical keypad and monochrome screen display.
Beyond its signature look, it easily gained the attention of Bitcoin purists with its exclusion of altcoin support. Coinkite’s decision to go in this direction minimized the device’s code complexity and attack surface.
Unlike most wallets that rely on USB or Bluetooth to communicate with a smartphone or a computer with an internet connection, Coinkite has made Coldcard completely air-gapped. It means the wallet signs transactions using out-of-band MicroSD cards or encrypted NFC (Near Field Communication). The hardware wallet’s lack of a companion app or cloud account effectively isolates its system from potential network intercepts, remote malware, or compromised host operating systems.
Additionally, Coldcard secures private keys with dual secure element (SE) chips. These are specialized, tamper-resistant components that safely store confidential data and run critical cryptographic functions. Likewise, it runs on an open-source firmware that users can easily verify and build from source to audit for backdoors or vulnerabilities.
Moreover, Coldcard can generate and vault BIP-39/BIP-85 seeds, recovery phrases, passwords, and private notes for other wallets. The feature enables users to derive isolated child seeds for secondary wallets without exposing the master key, alongside encrypted seed vault and password management options.
What Went Wrong with Coldcard?
Cybersecurity experts at Block recently uncovered a bug in Coldcard dating back to March 2021. The team found that the hardware wallet’s firmware, starting with the v4.0.0 release, had a critical integration error in how it gathered seed entropy.
Without delving too much into the technicalities, the configuration compromised the randomness with which the wallet generated private keys. The compromised entropy source made the wallet seeds it generated far more predictable than intended.
Attackers capitalized on the vulnerability by precomputing or brute-forcing their way into the seeds of affected Coldcard wallets. It allowed them to drain funds directly from victims’ wallets even without physically accessing or tampering with their hardware.
As CZ pointed out, hackers effectively turned the wallet’s air-gapped design from a key security feature to an opportunity. It provided them with a longer window to systematically sweep compromised keys before users even realized their devices’ vulnerability.
The platform’s always-offline element blocked automatic over-the-air (OTA) updates and real-time notices. The ways around the issue were limited to users manually checking and installing the updates or manually transferring their funds.
Coinkite’s Security Advisory
Coinkite immediately released a security advisory to guide affected Coldcard users. The notice contained links to several fixes for affected models and release tracks.
The company advised users against simply generating a seed on affected wallets until they have finished installing the necessary firmware updates. However, it reminded them that the update alone won’t save existing seeds that the wallet generated during its vulnerable phase.
Furthermore, Coinkite explained that updating the firmware only prevents the wallet from generating a seed phrase with the same bug. Bitcoin Well emphasized that the compromised master key, including every address derived from it, remains permanently vulnerable on-chain. Therefore, the best way for users to protect their funds and have peace of mind is to migrate to a different wallet.
On the other hand, Coinkite claimed that users who have implemented 50+ manual dice rolls during setup, added custom BIP-39 passphrases, and enforced multisig configurations weren’t affected by the exploit. Nonetheless, the abovementioned safeguards are still highly recommended.
Final Thoughts
The Coldcard wallet incident serves as a harsh reminder of the hard, cold truth about Bitcoin and crypto custody, regardless of whether users have chosen self-custody in cold wallets or entrusted their assets to third-party platforms. Security is a continuous process rather than a one-off deal.
Risks are everywhere, but due diligence and utmost vigilance make a huge difference in significantly mitigating them. Ultimately, taking control of one’s crypto assets carries a great deal of responsibility.
In Bitcoin, staying secure is an active, continuous commitment.
What’s your Reaction?
+1
4
+1
0
+1
1
+1
0
+1
0
+1
0
+1
0
