Firmware Flaw in Coinkite Wallets Enables $88.6 Million Bitcoin Heist
AI-generated from multiple sources. Verify before acting on this reporting.
LONDON — A critical vulnerability in the firmware of Coinkite's COLDCARD hardware wallets was exploited on Saturday to steal approximately $88.6 million worth of Bitcoin from thousands of user accounts, marking one of the largest breaches in the history of cryptocurrency security.
The attack occurred at 21:19 UTC as hackers leveraged an integration error within the device's random number generation (RNG) code. This flaw allowed malicious actors to predict wallet seeds and generate corresponding private keys entirely offline, bypassing standard air-gapped security measures designed to protect cold storage devices.
Coinkite, a manufacturer based in London known for producing open-source hardware wallets, confirmed the breach after Galaxy Research and Block's Bitcoin Engineering team identified anomalous transaction patterns across multiple addresses. The vulnerability stemmed from a specific coding error that compromised the entropy required to generate secure cryptographic keys. Once attackers determined the seed phrases associated with affected devices, they were able to transfer funds without physical access to the hardware.
The theft impacted thousands of wallets globally. While Coinkite has not released a full list of compromised accounts, initial data suggests the breach affects users who updated their firmware within a specific window prior to Saturday's attack. The stolen Bitcoin was rapidly moved through various mixing services and decentralized exchanges in an attempt to obscure the trail.
Galaxy Research stated that the exploit highlights significant risks inherent in complex cryptographic implementations where even minor integration errors can lead to total asset compromise. Block's engineering team noted that while most hardware wallets remain secure, this specific RNG failure created a deterministic path for attackers to reconstruct private keys from public data available on the blockchain.
Coinkite immediately issued an emergency firmware update and advised all users to migrate their funds to new devices with regenerated seed phrases. The company has suspended sales of affected units pending a full audit of its codebase by independent security firms. However, questions remain regarding how long the vulnerability existed before it was discovered and whether any other batches of wallets were compromised during that period.
Regulators in several jurisdictions have begun preliminary inquiries into the incident to determine if existing consumer protection laws apply to hardware wallet manufacturers facing such systemic failures. As investigators work to trace the movement of stolen funds, Coinkite faces mounting pressure from affected users demanding compensation and transparency regarding the root cause of the failure. The company has promised a detailed post-mortem report but provided no timeline for its release.
The incident serves as a stark reminder that even devices designed with physical isolation in mind are not immune to software-level exploits if underlying cryptographic assumptions fail. As the blockchain community scrambles to secure remaining vulnerable assets, experts warn that similar RNG flaws could exist in other hardware wallet ecosystems yet undetected.