Article analysis

THThe Hacker News
2w ago
TechTechnicalSecurity

Coldcard Hardware Wallet Flaw Linked to $70 Million Bitcoin Theft in 41 Minutes

An attacker drained 1,196 Bitcoin addresses in 41 minutes on July 30, taking 1,082.65 BTC worth about $70.2 million at the time. Galaxy Research mapped the sweep and tied it to a firmware flaw in Coldcard, the Bitcoin-only hardware wallet made by Canadian firm Coinkite. A March 2021 firmware integration error routed seed generation to a deterministic software pseudorandom number generator (PRNG

Confidence0%
Tilt0%

Skim this article about "Coldcard Hardware Wallet Flaw Linked to $70 Million Bitcoin Theft in 41 Minutes": 3 key takeaways and more.

Coldcard Hardware Wallet Flaw Linked to $70 Million Bitcoin Theft in 41 Minutes

skim AI Analysis | The Hacker News

The Hacker News on Coldcard Hardware Wallet Flaw Linked to $70 Million Bitcoin Theft in 41 Minutes: skim's analysis surfaces 3 key takeaways. A firmware flaw in Coldcard hardware wallets led to a $70. Read the takeaways in seconds, then decide whether the full article is worth your time.

Category: Tech. News article analyzed by skim.

Summary

A firmware flaw in Coldcard hardware wallets led to a $70.2 million Bitcoin theft in 41 minutes. The flaw, a March 2021 integration error, routed seed generation to a deterministic PRNG instead of a hardware RNG. Coinkite has released emergency firmware, but users with exposed seeds must generate new ones and move their coins.

Key Takeaways

  1. An attacker drained 1,196 Bitcoin addresses in 41 minutes on July 30, taking 1,082.65 BTC worth about $70.2 million at the time.
  2. Galaxy Research mapped the sweep and tied it to a firmware flaw in Coldcard, the Bitcoin-only hardware wallet made by Canadian firm Coinkite.
  3. A March 2021 firmware integration error routed seed generation to a deterministic software pseudorandom number generator (PRNG) instead of the STM32 hardware random number generator (RNG).

Statement Breakdown

  • Claimed Facts: 70% of statements the article presents as facts
  • Opinions: 20% of statements classified as editorial or subjective
  • Claims: 10% of statements surfaced for additional reader evaluation

Credibility & Bias Reasoning

Credibility assessment: The article presents a detailed technical analysis of a security flaw and its consequences. It cites research from Galaxy Research and Block, providing specific details about the exploit. However, it relies on a single source for the primary information.

Bias assessment: Technical Security Reporting. The article focuses on reporting a technical vulnerability and its impact on a specific hardware wallet. The language is objective and descriptive, aiming to inform readers about a security incident rather than promote a particular viewpoint.

Note: This article details a complex technical security flaw. While it provides specific information, readers should cross-reference with official statements from Coinkite and further security analyses for a comprehensive understanding.

Credibility flag: Technical, Verify Details

Claimed Facts (8)

  • This is a factual statement about the event, including the number of addresses, time, amount of Bitcoin, and its value.
  • This states a finding by Galaxy Research and identifies the affected product and manufacturer.
  • This provides a specific technical detail about the nature of the firmware flaw.
  • This describes the method by which an attacker can exploit the flaw, according to Block.
  • This states a fact about Coinkite's response and its limitations.
  • This relays the official recommendation from Coinkite to affected users.
  • This is a factual statement about the persistence of the vulnerability if the old seed is reused.
  • This provides a specific technical detail about the origin of the flaw within the code configuration.

Opinions (8)

  • While this describes a process, the certainty of 'can then be checked' implies a degree of interpretation of the technical possibility.
  • The statement about 'collected no fresh entropy' is an interpretation of the system's behavior based on the initialization process.
  • These are estimations provided by Coinkite, representing their assessment of the entropy levels.
  • This is an observation about the content provided by Block, an opinion on what is or isn't included.
  • This describes Block's interpretation and warning regarding certain security metrics.
  • This is an observation about the absence of specific data from Block, an opinion on their publication.
  • This includes Block's assessment of factors influencing the practical cost of an attack.
  • This is a statement of dependency, an interpretation of how the vulnerability is triggered.

Claims (5)

  • This statement asserts a lack of public information, which is difficult to definitively prove or disprove without exhaustive searching.
  • This is a definitive statement about the identity of the attacker, which is often unknown in such cases and difficult to verify absolutely.
  • While presented as a finding, the absolute claim of 'no other transactions' is a strong assertion that is hard to verify without access to all transaction data and analysis tools.
  • The quote itself is an interpretation of how the transaction pattern appears, and the assertion that it 'identifies the operator, not the theft' is a nuanced claim about attribution.
  • While likely factual, the precise attribution of '$5 million drained' from 'older software wallets' due to a 'separate weak-PRNG flaw' is a complex claim that could be subject to further verification and might be an aggregation of various reports.

Key Sources

  • The Hacker News — News Outlet
  • Galaxy Research — Research Firm
  • Block — Research Entity (likely related to Square/Block, Inc.)
  • Coinkite — Hardware Wallet Manufacturer
  • Coinspect — Security Research Firm

This analysis was generated by skim (skim.plus), an AI-powered content analysis platform by Credible AI. Scores and classifications represent the platform's AI-generated assessment and should be considered alongside other sources.

skim analyzes recent The Hacker News coverage for what holds up, what reads as opinion, and what may not be fully supported. Last updated 1st August 2026.