Summary Peter Todd warned Coldcard vulnerabilities exposed single-signature Bitcoin wallets following researchers linking flaws to $38.3 million theft involving 594.48 BTC. Block Security rep
Summary
- Peter Todd warned Coldcard vulnerabilities exposed single-signature Bitcoin wallets following researchers linking flaws to $38.3 million theft involving 594.48 BTC.
- Block Security reported older devices generated predictable seed phrases while newer models truncated entropy, reducing wallet security across multiple versions.
- Experts urged affected users to create entirely new wallet seeds because exporting existing recovery phrases leaves funds vulnerable despite migration.
Bitcoin developer Peter Todd has warned that single-signature Bitcoin wallets face serious security risks following the disclosure of critical vulnerabilities in Coldcard hardware wallets. His warning follows findings from security researchers who linked the flaws to a theft involving nearly 600 BTC, raising wider concerns about how hardware wallets generate recovery seed phrases.
According to Block Security, attackers transferred 594.48 BTC, valued at approximately $38.3 million, into a single wallet after exploiting weaknesses that made affected wallets easier to compromise.
Peter Todd questions hardware wallet security
According to Peter Todd in a post on X, the Coldcard incident reinforces concerns he has expressed for years about commercial hardware wallets. He argued that users trust devices running code that receives limited independent scrutiny while also relying on hardware that could face supply chain risks. Additionally, Block Security reported that the vulnerability has existed since March 2021 and affects several Coldcard models, including the Mk2, Mk3, Mk4, Q and Mk5.
Also Read: Binance Coin Trading Volume Jumps 65% as Bullish Positioning Strengthens
Researchers explained that older devices accidentally disabled their hardware random number generator because of a software error. Consequently, those wallets generated recovery seeds through a predictable software process instead of using dedicated hardware entropy.
Meanwhile, newer models reportedly truncated critical entropy during seed generation, significantly reducing the number of possible recovery phrase combinations. As a result, attackers could brute-force vulnerable wallets using conventional computing resources within a short period.
Besides criticizing the existing design, Todd urged the industry to adopt deterministic testing for physical hardware. He argued that developers should verify the source of wallet entropy instead of assuming hardware functions correctly. He also demonstrated manual seed generation using a deck of cards and referenced his earlier proposal for a button-based random number generator.
Furthermore, Block Security warned that multisignature wallets are not automatically protected if every signing key originated from vulnerable Coldcard devices. The researchers explained that exporting an existing recovery phrase to another wallet does not remove the original weakness because the flaw occurs during seed creation.
Experts therefore advised affected users to generate a completely new seed phrase on unaffected hardware before transferring Bitcoin into newly created wallet addresses. However, users who enabled an additional BIP-39 passphrase during the original setup remain protected because that extra layer substantially increases resistance against brute-force attacks.
Conclusion
The Coldcard vulnerability has renewed attention on hardware wallet security and the importance of secure seed generation. Moreover, Todd’s warning and Block Security’s findings highlight that affected users must create entirely new wallets instead of relying on existing recovery phrases to safeguard their Bitcoin holdings.
Also Read: RLUSD expands AI payment role with Google and Mastercard protocol support
The post Peter Todd warns Coldcard flaw leaves Bitcoin single-signature wallets exposed appeared first on 36Crypto.