A blockchain engineer has revealed that the attacker behind the Coldcard hardware wallet exploit used a commercial blockchain services provider to execute the theft, which has now exceeded $70 million in Bitcoin. The disclosure adds another dimension to the ongoing security crisis affecting Coinkite's hardware wallet product line.
Investigation Uncovers Commercial Infrastructure Use
Clay Garrett, an engineer at payments company Block, announced Friday that his investigation identified an unusual pattern in how the stolen Bitcoin was moved. The analysis revealed that the attacker maintained a paid account with an established blockchain services provider to query source addresses and coordinate the systematic draining of vulnerable wallets.
The pattern matching led to confirmation from the unnamed provider, who requested anonymity but cooperated with investigators. Garrett stated that law enforcement has been notified of the findings. Galaxy Digital's research division independently confirmed the unusual movement patterns indicated a single coordinated attacker rather than multiple separate incidents.
Firmware Vulnerability Affects All Coldcard Models
Coinkite initially disclosed Thursday that a firmware bug in Coldcard Mk3 devices running version 4.0.1 or later (released March 2021) caused the seed generation process to use a weak software-based pseudorandom number generator instead of the intended hardware true random number generator. This made private keys for single-signature wallets predictable and vulnerable to brute-force attacks, particularly those created without dice rolls or strong BIP-39 passphrases.
By Friday, Coinkite confirmed the vulnerability extends to all its hardware wallet models following additional thefts. Engineers have warned that more Bitcoin addresses remain at risk, with losses currently surpassing $70 million.
Implications for Web3 Security Professionals
This incident highlights critical vulnerabilities in hardware wallet development and the security infrastructure that blockchain professionals rely on. For security engineers and developers in the crypto industry, the case demonstrates how implementation flaws in random number generation can persist undetected for years, even in products marketed for secure cold storage.
The revelation that commercial blockchain services facilitated the attack also raises questions about operational security practices and the potential for infrastructure providers to become inadvertent accomplices. Web3 security professionals should expect increased scrutiny of hardware wallet implementations and random number generation processes across the industry.


