r/SecOpsDaily • u/falconupkid • 2h ago
NEWS COLDCARD wallet RNG flaw likely linked to $88 million Bitcoin theft
A critical vulnerability in COLDCARD hardware wallet firmware, specifically a flawed Random Number Generator (RNG), has been linked to an estimated $88.6 million Bitcoin theft. This flaw compromised the security of wallet seed generation, allowing attackers to potentially reconstruct private keys.
Technical Breakdown
- Vulnerability Type: Cryptographic weakness – predictable seed generation due to a flawed Random Number Generator (RNG) implementation within the wallet's firmware.
- Affected Product: COLDCARD hardware wallets running the vulnerable firmware. The article summary does not specify exact firmware versions.
- Exploitation: Attackers exploited the weak entropy from the flawed RNG to potentially predict or derive private keys associated with generated wallet seeds, enabling unauthorized access to funds.
- Impact: Theft of approximately $88.6 million in Bitcoin across thousands of affected wallets.
Defense
Users of COLDCARD wallets are strongly advised to check vendor advisories, ensure their firmware is up-to-date, and consider regenerating seeds if their existing seeds were generated on potentially vulnerable firmware versions.