Threat Intelligence Brief
Curated summary with source attribution
Source: coindesk.com
Threat Risk: High
Victim: Coldcard hardware wallet users
Incident: Attackers exploited a firmware flaw in Coldcard devices to reconstruct private keys and drain funds.
Impact: Approximately 1,082.65 BTC, valued at $70 million, was stolen from 1,196 addresses.
Attacker: Unidentified threat actors
Analysis: The exploit targeted a weakness in the randomness used for recovery seed generation in specific Coldcard models. Because the flaw existed in the firmware since 2021, attackers could reconstruct private keys offline without needing physical access to the devices. This incident highlights the risk of dormant cryptographic bugs in trusted security hardware.
Recommendations: Update Coldcard firmware immediately to the latest patched version.; Generate entirely new recovery seeds on patched devices as firmware updates alone cannot fix existing vulnerable seeds.; Diversify assets across multiple hardware wallet brands to mitigate single-point-of-failure risks.
Source: CoinDesk
Editorial note: this post summarizes third-party reporting and links to the original source.
View Original Source