Coldcard Mk3 Flaw Exposes 594 BTC to Theft in 25-Minute Attack

Editorial illustration for: Coldcard hardware wallet flaw exposes 594 BTC to theft in 25-minute attack

In brief

  • 594 BTC ($38M) stolen from ~500 Coldcard Mk3 wallets in 25-minute attack window
  • Firmware bug: randomness generator bypassed, fell back to serial number and clock values
  • Mk3 firmware 4.0.1+ affected; Mk4, Q, Mk5 models unaffected by vulnerability
  • Block published findings mid-exploitation to prevent further wallet compromise
  • Bitcoin price remained above $64K with minimal market reaction to the drain

The Flaw

Coldcard is a hardware wallet built by Canadian firm Coinkite that stores bitcoin keys offline. The device includes its own hardware randomness generator for creating cryptographic seeds. But Coldcard's firmware was not using that hardware generator. Instead, a build setting told the device to skip the secure random source entirely.

Key generation fell back to a basic software substitute. The substitute was seeded from the chip's serial number and clock registers. Neither source is secret. The serial number is fixed factory metadata, and the clock values are timing state an attacker can narrow down or measure on a device of their own.

With those two inputs, an attacker could derive the private keys behind wallets generated on a vulnerable device. The math became tractable.

Scope and Timeline

The randomness flaw was traced to a commit dated March 1, 2021, shipped in firmware 4.0.0 that month. Coinkite warned users who generated a seed on an Mk3 running version 4.0.1 or later. The company stated that Mk4, Q, and Mk5 models are not affected based on early analysis.

The exposure runs deeper than wallet seeds alone. The same randomness generator flaw affected Coldcard's paper wallet private keys, seed-splitting masks, device cloning keys, and Key Teleport transfers.

Every drained wallet was single-signature and each held more than 0.15 BTC. Many had been dormant for years, with coins spanning 2021 to 2026. That dormancy meant owners might not notice the loss for weeks or months.

Publication and Market Impact

Block, a Bitcoin engineering and security firm, published its findings without full testing to confirm exploitability. The reason: exploitation was already under way. The team chose disclosure over silence because the attack was live.

Bitcoin traded above $64,000 in early Asian hours following the drain. The widespread theft appeared to have little immediate impact on the market.