NewsCryptoColdcard Bitcoin Thief Likely Used Major Blockchain Services Provider, Investigation Reveals

Coldcard Bitcoin Thief Likely Used Major Blockchain Services Provider, Investigation Reveals

Author: Bitcoin Magazine·

Key Takeaways

  • The exploit originated from a firmware bug introduced in Coldcard version 4.0.1 in March 2021, which caused seed generation to use a weak pseudorandom number generator instead of the intended hardware true random number generator.
  • Over $70 million in Bitcoin has been stolen, with engineers warning that additional addresses may still be at risk as Coinkite has acknowledged all device models are affected.
  • Investigators identified that the attacker used a paid account at a well-known blockchain services provider to query source addresses and execute sweeps of the stolen funds.
  • Wallets created without dice rolls or a strong BIP-39 passphrase during the three-plus-year vulnerability window are particularly susceptible, as their private keys could be brute-forced due to compromised entropy.
  • Galaxy Digital's research team observed a distinctive on-chain pattern confirming a single attacker was responsible and recommended that users relocate funds from single-signature Coldcard addresses to more secure custody arrangements.
Coldcard Bitcoin Thief Likely Used Major Blockchain Services Provider, Investigation Reveals

Following the theft of over $70 million in Bitcoin through an exploit targeting Coldcard's hardware wallets, investigators have determined that the attacker likely utilized a prominent blockchain services provider to facilitate the sweeping of stolen funds.

Clay Garrett, an engineer at payments company Block, disclosed the finding on X (formerly Twitter) on Friday. He stated that the provider — whose identity was withheld at their own request — was identified after on-chain movements aligned with what he described as the attacker's "suspected workflow." The provider has since been contacted.

"During our investigation of the Coldcard drain yesterday, we identified an unusual pattern in the sweeps," Garrett wrote.

"That pattern led us to a hypothesis that has since been confirmed: the operator used a paid account at a well-known blockchain-services provider to query the source addresses and perform other related activity during the sweeps," Garrett continued, noting that authorities had been notified.

Galaxy Digital's research arm echoed the observation on X, stating that the thief exhibited a distinctive pattern in moving the stolen coins.

"The pattern tells us these were all the same attacker — it does not capture the attack itself, which looks the same as if a coin owner chose to move coins," the firm wrote, urging Bitcoin users to relocate funds from single-signature Coldcard addresses to more secure custody arrangements.

The exploit traces back to a firmware vulnerability in Coldcard Mk3 devices, according to Coinkite, the company that manufactures Coldcard products. Coldcard devices are marketed as air-gapped, Bitcoin-only hardware wallets designed for self-custody, making a key-generation flaw particularly significant for users who selected the product specifically for its security features.

The bug, present starting with firmware version 4.0.1 released in March 2021, caused seed generation to fall back to a weak software pseudorandom number generator rather than the device's hardware true random number generator. Because the vulnerability went undetected for over three years, wallets created at any point during that window — not just recently — may carry keys derived from compromised entropy.

This flaw rendered private keys for many single-signature wallets — particularly those created without dice rolls or a strong BIP-39 passphrase — predictable enough for attackers to brute-force. Weak entropy in random number generation has been a documented failure mode across cryptocurrency systems, and its presence in a hardware wallet underscores that offline key storage alone does not guarantee randomness quality at the point of seed creation.

After over $35 million was initially drained on Thursday, additional thefts followed. By Friday, Coinkite acknowledged that all of its device models were affected. The total stolen has surpassed $70 million, and engineers have cautioned that more Bitcoin addresses may still be at risk.

Coinkite produces a range of Bitcoin security products, including cold storage hardware wallets.