In section Cryptocurrency

Coldcard Users Urged to Migrate Seeds After $88 Million Bitcoin Theft

Dogecoin contributor Mishaboar has issued an urgent directive for Coldcard users to abandon existing seed phrases and migrate funds to new wallets immediately. This follows a security breach where 1,367 BTC, valued at approximately $88.6 million, was drained from thousands of addresses due to a firmware-level vulnerability in seed generation.

Coldcard Users Urged to Migrate Seeds After $88 Million Bitcoin Theft

The security flaw, identified by Block’s engineering team, stems from a firmware integration error that caused affected devices to utilize a deterministic MicroPython fallback rather than the intended hardware random-number generator. This failure effectively stripped the seed creation process of necessary cryptographic entropy. While Coinkite has released firmware patches to rectify the generation process for new wallets, the manufacturer confirmed that updates cannot retroactively secure existing, compromised seeds.

Galaxy Research reported three distinct attack waves, noting a shift in tactics from targeting large holdings to sweeping smaller wallets. Investigators found that 4,585 addresses were compromised, with the attackers successfully reproducing weak private keys offline. Because the vulnerability lies within the third-party firmware rather than the Bitcoin protocol itself, the transactions appeared legitimate on-chain, complicating recovery efforts. Coinkite maintains that users who incorporated at least 50 independent dice rolls during seed creation may possess sufficient entropy, though the company generally recommends a full migration for all users of the affected firmware versions, which include models from the Mk2, Mk3, Mk4, and Mk5 series.

Share:on TelegramXFacebook

Subscribe to our newsletter

Once a week — the best stories from our editors, no ads or push notifications. Delivered Sunday morning.

Comments (0)

Leave a comment

No comments yet. Be the first!