Crypto

Coldcard Cold Wallet Flaw Enables $70M Theft

724FinanceCem Talu
Key Highlights

Bitcoin soğuk cüzdanların **$70 milyon**'lık çalınması, kripto güvenliğinde yeni bir alarm sinyali verdi. ## Soğuk Cüzdan Saldırısının Detayları Gal

Coldcard Cold Wallet Flaw Enables $70M Theft

The theft of $70 million from Bitcoin cold wallets has sounded a new alarm for crypto security.

Anatomy of the Cold Wallet Breach

Galaxy Research uncovered that 1,196 wallets lost 1,082.65 BTC within a 41‑minute window, from 01:10 to 01:51 UTC. The transactions were broadcast in batches across six blocks.

  • 1,183 wallets used the modern segwit address format.

  • Only 7 wallets employed an older standard, and 6 used an even older format.

  • The stolen funds now sit in four addresses and have not moved.
  • The Technical Failure

    Coldcard's firmware was configured to skip its dedicated hardware randomness generator. Consequently, key generation fell back to a simple software seed derived from the device's serial number and clock registers. This collapsed the keyspace to roughly four billion possibilities – a tractable target for a computer.

  • Affected models include Mk2, Mk3, Mk4, Q, and Mk5.

  • Coinkite warned only Mk3 owners, while Block’s report broadened the scope.

  • The attacker generated candidate seeds on their own hardware, matched resulting addresses against the public blockchain, and never needed to touch the victim’s device.
  • Market and User Repercussions

    The incident undermines confidence in offline storage solutions and pushes crypto asset managers toward immediate remedial actions. Major exchanges like Binance are expanding secure custody services while users grow increasingly wary.

  • Coinkite advises affected users to move their funds promptly.

  • Block revealed the attacker used a paid account at a well‑known blockchain data provider to query source addresses.

  • Information passed to authorities may trigger legal scrutiny.
  • Future Risks and Recommendations

    The core security premise of cold wallets – an unguessable key – is now in question. The lack of a self‑test to verify whether a seed falls within the compromised range makes detection difficult.

  • Hardware manufacturers should re‑audit their randomness sources.

  • Users must install new firmware updates as soon as possible.

  • Multi‑signature and offline backup strategies can mitigate single‑device failures.
  • Cem Talu – Cold‑wallet security is the backbone of the crypto ecosystem. This breach not only exposes a hardware flaw but also highlights the need for holistic risk management and continuous auditing. Developers should embed full‑proof randomness verification mechanisms, and users must adopt layered defenses to prevent similar large‑scale losses in the future.

    Related News & Analysis

    View All →

    Latest Market News

    All News →
    C

    Financial Analyst: Cem Talu

    Software-oriented blockchain researcher and crypto investor. Innovative, technology-focused.

    Disclaimer: The investment information, comments, and recommendations contained herein are not within the scope of investment advisory. Investment advisory services are provided individually by authorized institutions, taking into account the risk and return preferences of individuals. The comments and recommendations contained herein are general in nature. These recommendations may not be suitable for your financial situation and your risk and return preferences. Therefore, making an investment decision based solely on the information contained herein may not produce results that meet your expectations.

    © 2026 724Finance - All Rights Reserved.Original Source: CoinDesk