A critical firmware vulnerability in Coldcard hardware wallets has led to ongoing Bitcoin thefts totaling over $114 million, exposing significant security gaps in cold storage solutions and highlighting the critical importance of security engineering roles in the cryptocurrency industry.
Multiple Attack Waves Target Coldcard Users
The theft began Thursday with hackers draining over $35 million in Bitcoin from affected wallets. A fourth wave of attacks commenced Sunday evening, with Galaxy Research's Alex Thorn reporting that 388.9 BTC worth approximately $29 million was moved in new transactions consistent with the ongoing exploit.
Coinkite, the manufacturer of Coldcard devices, identified the root cause as a firmware bug affecting Mk3 devices running version 4.0.1 or later, released in March 2021. The vulnerability caused seed generation to default to a weak software-based Pseudorandom Number Generator rather than the intended hardware true random number generator. This flaw allowed attackers to effectively predict users' seed phrases and access their funds.
The company initially stated only Mk3 devices were compromised but later confirmed all Coldcard models contain the vulnerability, prompting engineers to warn that any Bitcoin address associated with Coldcard wallets could eventually face risk.
Industry Response and Aftermath
Coinkite has halted all shipments and destroyed remaining inventory manufactured with the compromised firmware. In a statement Sunday, the company acknowledged the severity of the incident, describing the past three days as "some of the hardest in this company's history."
Engineers at Block investigated the exploit and discovered hackers utilized a major blockchain services provider to facilitate fund transfers. Block has notified both the provider and federal authorities of their findings.
Implications for Web3 Security Professionals
This incident underscores the growing demand for rigorous security engineering and cryptographic expertise in the blockchain sector. Hardware wallet manufacturers will likely increase hiring for security auditors, cryptography specialists, and quality assurance engineers to prevent similar vulnerabilities. For professionals in blockchain security, this event demonstrates the critical need for comprehensive code review processes and the potentially catastrophic consequences of implementation flaws in production systems.
The breach serves as a reminder that even cold storage solutions require ongoing security assessment, creating opportunities for professionals specializing in hardware security and penetration testing within the cryptocurrency ecosystem.


