Coldcard漏洞已影响超4500个地址,近9000万美元比特币被盗
2026-08-03 04:21
Odaily News: Kraken Chief Security Officer Nick Percoco stated that the five-year seed generation vulnerability in Coldcard has exposed gaps in independent testing of hardware wallets. Auditors verified that the expected random number generator exists but did not verify that production firmware actually invokes that generator.
The vulnerability is believed to be linked to an ongoing attack. As of Sunday, over 4,500 addresses have been affected, with nearly $90 million in Bitcoin stolen. Coinkite disclosed that the software vulnerability has existed since March 2021. When Coldcard integrated a new cryptographic library, the wallet creation process was mistakenly redirected to a weaker MicroPython generator.
Percoco noted that hardware wallets lack end-to-end verification processes similar to NIST SP 800-90B and BSI AIS-31. Existing security element Common Criteria certifications, partial CSPN certifications, and vendor-commissioned audits have not systematically enforced verification that production firmware calls validated entropy sources.
Coldcard stated that it has suspended all device shipments since confirming the vulnerability on Thursday and has destroyed all remaining devices containing affected firmware at its facility. Coinkite advised affected device users not to discard their devices and said its legal team will coordinate with law enforcement agencies across multiple jurisdictions as appropriate.
The vulnerability is believed to be linked to an ongoing attack. As of Sunday, over 4,500 addresses have been affected, with nearly $90 million in Bitcoin stolen. Coinkite disclosed that the software vulnerability has existed since March 2021. When Coldcard integrated a new cryptographic library, the wallet creation process was mistakenly redirected to a weaker MicroPython generator.
Percoco noted that hardware wallets lack end-to-end verification processes similar to NIST SP 800-90B and BSI AIS-31. Existing security element Common Criteria certifications, partial CSPN certifications, and vendor-commissioned audits have not systematically enforced verification that production firmware calls validated entropy sources.
Coldcard stated that it has suspended all device shipments since confirming the vulnerability on Thursday and has destroyed all remaining devices containing affected firmware at its facility. Coinkite advised affected device users not to discard their devices and said its legal team will coordinate with law enforcement agencies across multiple jurisdictions as appropriate.
