- The Beluga Brief
- Posts
- š³ Weekly Edition: Hundreds of Crypto Wallets Drained in Coldcard Exploit
š³ Weekly Edition: Hundreds of Crypto Wallets Drained in Coldcard Exploit
A hacker discovered a Coldcard hardware wallet bug which made seed phrases guessable due to poor randomization.

Over 1,000 Bitcoin was drained from 1,200 Coldcard hardware wallets today after a hacker exploited a bug introduced in a March 2021 firmware update. Many of these wallets had been sitting dormant for years and were targeted because of their high balances (minimum 0.15 BTC). None of the wallets were physically accessed, there was no wrench attack and phishing wasn't involved. So how did the hackers do it?
In order to understand the exploit, you first have to understand entropy. Entropy is a measure of randomness. The higher the entropy, the harder something is to guess. Guessing a random number between 1 and a billion is much more difficult than guessing a number between 1 and 10. Bitcoin seed phrases are randomly generated. The higher the entropy during the generation process, the harder the seed phrase is to crack.
Coldcard wallets have a True Random Number Generator (TRNG) that samples from the environment around it to generate high-entropy seed phrases. In 2021, Coldcard shipped a software update that accidentally caused wallets to generate keys using a Pseudorandom Number Generator (PRNG) instead of the onboard TRNG chip. PRNGs have much lower entropy and are vulnerable to brute-force attacks.
A hacker discovered the issue and was able to drain affected Coldcard wallets because the seed phrases weren't truly random and were therefore guessable. The stolen funds have been consolidated into a handful of wallets, but at the time of writing, they haven't been moved into a mixer or privacy coin.
Should you be worried? If you have a Coldcard Mk3 that generated its seed phrase on firmware versions 4.0.1 through 4.1.9, you should move your funds to a new wallet immediately. Updating the firmware alone doesn't solve the problem. You also need to generate a new seed phrase.
I'd imagine almost none of you are affected. If you're using a different hardware wallet, you likely have nothing to worry about. This exploit was caused by a specific bug in Coldcard's software. The major hardware wallet providers generate seed phrases with high entropy and have a good track record of keeping funds safe.
The most common way people lose crypto is by giving someone their seed phrase. As long as you can avoid that, you've won 90% of the battle.

The Beluga intern has been hard at work gathering all the most important crypto news stories so you have them in one place!
The Majors
Alt Coins and Stocks
Crime
AI
Interesting Reads

Check out our latest content below!


