Five-Year Coldcard Wallet Vulnerability Exposed: $90 Million in Bitcoin Stolen
A five-year flaw in Coldcard hardware wallets, uncovered by Kraken's security chief, allowed attackers to drain about $90 million in Bitcoin from over 4,500 addresses. Coldcard halted shipments of affected devices.
Kraken's Director of Security, Nick Percoco, revealed that a critical flaw in Coldcard hardware wallets went undetected for five years, highlighting testing gaps. Independent auditors checked for a secure random number generator but failed to confirm the firmware actually employed it.
The weakness reportedly enabled an attack that compromised over 4,500 Bitcoin addresses, siphoning nearly $90 million. The stolen funds were withdrawn from affected wallets, according to reports.
In response, Coldcard has halted shipments of devices running the vulnerable firmware. The incident raises questions about the rigor of security audits for hardware cryptocurrency wallets.
Source: ForkLog