Coldcard's firmware checked whether a configuration macro existed instead of whether it was switched on. It existed and it was set to zero, so five years of wallets built their recovery seeds from a fallback pseudo-random generator, and an attacker swept roughly 1,082 BTC out of 1,196 addresses in 41 minutes.

Read the full story: A one-line firmware check cost Coldcard users 1,082 BTC →

Transcript

The bug is about as small as a bug can get. Coldcard's firmware asked whether a configuration setting existed, rather than whether it was switched on. It existed, and it was set to zero. So for five years the devices built recovery seeds from a fallback pseudo-random generator instead of the hardware randomness chip sitting right there on the board. That fallback was seeded from the chip's serial number and its timers. Neither of those is secret. What should have been a hundred and twenty eight bits of unguessable randomness came out closer to forty on the older devices. On July thirtieth somebody who had worked this out swept eleven hundred and ninety six addresses in forty one minutes, taking about one thousand and eighty two bitcoin. Coinkite has taken responsibility and shipped emergency firmware. Here is the part people are missing. That update does not repair a seed you already have. If yours was generated on an affected build, you need a brand new seed and you need to move every coin to it.