Via bitrawr.com
Block traces COLDCARD attacker to blockchain services provider after $38M Bitcoin theft
Engineers followed the trail from a five-year-old firmware bug to the entity that drained 594 BTC from 500 wallets in under 25 minutes
Block’s engineering team has identified the entity behind the COLDCARD hardware wallet exploit, tracing the attacker to a blockchain services provider that was used during the theft.
The breach, which occurred on July 30, drained approximately 594 BTC, worth roughly $38M, from around 500 wallets in a 25-minute window between 01:31 and 01:56 UTC.
A five-year-old firmware bug made it all possible
The root cause traces back to a firmware update from March 2021, specifically version 4.0.0, which deactivated the hardware random number generator on affected COLDCARD devices. The hardware RNG was replaced with a predictable software fallback that used non-secret seed values, meaning an attacker who understood the flaw could replicate wallet seeds derived from device-specific metadata. The affected devices were primarily Mk3 models and some Mk2 units where seeds had been generated under the compromised firmware.
The attacker apparently sat on this knowledge for years, targeting dormant accounts. The 25-minute execution window suggests extensive preparation, with the attacker having pre-computed the vulnerable seeds and scripted the draining process.
Block and Coinkite coordinated urgent disclosure
Block’s engineers, working alongside Coinkite (the company that manufactures COLDCARD), traced the attacker’s on-chain activity to a blockchain services provider. The collaboration enabled what both parties described as urgent disclosure of the vulnerability before full technical details were made public.
Coinkite issued an immediate advisory for users of Mk3 and older models who had generated seeds under the compromised firmware versions. The company’s preliminary assessment indicated that newer models, including Mk4, Q, and Mk5, were not affected by the RNG flaw. The recommended action was to generate entirely new seeds on unaffected hardware and migrate all funds immediately.
What this means for hardware wallet users and the broader market
Bitcoin was trading above $64K during the incident, and the market impact was minimal. The firmware update that introduced the vulnerability was v4.0.0, applied in March 2021. Users who applied that update thought they were improving their security but were instead generating seeds with a compromised RNG.