
Guides2 min read
The Robot news gave PI a boost
Pi Network's $PI token received a short-term price boost this week after Fabric Foundation (@FabricFND) announced that @PiCoreTeam had joined RoboPay as a payment partner. The news landed on
Galaxy Research has revealed that at least 15 different attackers are actively exploiting a critical vulnerability in certain Coldcard hardware wallets, leading to losses exceeding $130 milli
Galaxy Research has revealed that at least 15 different attackers are actively exploiting a critical vulnerability in certain Coldcard hardware wallets, leading to losses exceeding $130 million in Bitcoin. The attack has compromised over 7,300 wallets, and security experts warn that ongoing risks remain as the vulnerability continues to be exploited.
Coldcard, a hardware wallet designed by Coinkite for securely storing Bitcoin, faced a firmware flaw that weakened the generation of wallet private keys. According to researchers, the vulnerability allowed attackers to identify and target exposed wallet addresses, identifiable on Bitcoin’s public blockchain. Hackers then used brute-force methods to reconstruct private keys and access funds.
The primary cause was identified as a software bug in certain Coldcard firmware versions. Instead of generating wallet seeds using a true random number generator, the affected firmware relied on MicroPython’s software fallback, significantly reducing the entropy of the created seed phrases.
Because the vulnerability became well-known, any attacker with sufficient technical skill could exploit the issue, further widening the threat. Victims span both recent and long-term Bitcoin holders, with some users potentially unaware their wallets remain compromised.
Mini dictionary: Entropy, in cryptography, refers to the randomness and unpredictability necessary for secure cryptographic processes. Higher entropy means stronger, more secure keys, while reduced entropy makes keys easier for attackers to guess or brute-force.
Coinkite estimated that Coldcard Mk2 and Mk3 devices delivered only 40 bits of entropy for seed generation, far below the 128-bit industry target. The newer Coldcard Mk4 model reportedly improved this to 72 bits, yet this also remains under the company’s expected security threshold.
Coldcard ModelReported EntropyCompany Security TargetMk2 / Mk340 bits128 bitsMk472 bits128 bitsDue to these vulnerabilities, attackers were able to target thousands of wallets and drain substantial amounts of Bitcoin. Galaxy Research has received reports from dozens of victims, but the actual number of affected wallets may be considerably higher.
Coinkite’s co-founder Rodolfo Novak publicly apologized for the firmware bug, acknowledging the company’s responsibility and informing users about hotfixes that have been released for every affected wallet model and firmware version. On July 31, Novak addressed Coldcard users directly, reaffirming their commitment to resolving the issue.
Rodolfo Novak stated that Coinkite takes full accountability for the firmware bug and has issued urgent updates, but he warned that “the threat is still active” for users who have not yet migrated their Bitcoin to new, unaffected wallets.
Users who generated seeds on exposed firmware versions are urged to move their funds immediately, as vulnerable wallets remain visible and accessible to potential attackers on the blockchain. The identity of the attacker or attackers remains unknown as of now.
Experts stress the importance of generating wallet seeds only on secure and updated hardware to minimize risk. Galaxy Research and Coinkite both recommend that any Bitcoin held in affected wallets should be promptly transferred to new, secure wallets generated by devices with the latest firmware updates.
Coldcard users face continued risk until funds are transferred to wallets with seeds generated by secure, patched firmware.
As the issue remains active and technically accessible, users who delay action may continue to be exposed to theft attempts. Coinkite and wallet security researchers encourage vigilance and swift action to mitigate ongoing exposure.
The post Coldcard wallet bug exposes over $130 million in Bitcoin, 7,300 wallets impacted appeared first on COINTURK NEWS.