In just 25 minutes, 594.5 BTC worth over $38 million disappeared from approximately 500 Bitcoin wallets. Security researchers point to a possible common denominator: older Coldcard Mk3 devices running specific software versions. The manufacturer issued an urgent message and users should check as soon as possible whether their wallet is not in the risk group.
Nearly 600 BTC disappeared in one coordinated action
The cryptocurrency market has received information about one of the most disturbing security incidents in recent months. According to analyzes of blockchain researchers and the Bitcoin community from around 500 single-signature wallets taken out 594.5 BTCi.e. the equivalent of approx $38.3 million.
The funds were cleared in an extremely short time. The attacker was to take over 1324 UTXO distributed among approximately 500 transactionsand the entire operation was carried out in just three Bitcoin blocksor about 25 minutes.
This indicates a very well-prepared and automated action.
What connects the injured?
What’s most disturbing is that many of the compromised wallets remained unused for years. Therefore, it does not look like classic phishing or malware installed on users’ computers.
Researchers noted several common elements:
- all confirmed victims used wallets single-signature,
- no cases of wallet theft have been confirmed multisig,
- each victim had at least 0.15 BTCwhich may suggest that the attacker only selected more valuable wallets.
This led investigators to the hypothesis that all the devices may have shared a common vulnerability.
Suspicion fell on Coldcard Mk3
This is extremely important information because the security of the hardware wallet is based on generating a completely unpredictable seed. If the randomness generation process was faulty, it becomes theoretically possible to recreate the private keys by someone who discovers how the generator works.
However, the manufacturer emphasizes that the situation is being analyzed and it has not yet been definitively confirmed that this vulnerability is responsible for all the thefts.
Why is the randomness problem so dangerous?
In an extreme case, a person who knows how the faulty generator works could recreate the seed and gain access to the funds without physical contact with the device. At the current stage of the investigation, however, there is no public evidence that exactly such a mechanism was used by the perpetrators.
What should Coldcard Mk3 users do?
If you use Coldcard Mk3and the seed was generated on the firmware 4.0.1–5.0.3experts recommend extreme caution.
The most important recommendations are:
- creation a new wallet with a completely new seed,
- transferring all funds to a new address,
- not using the old recovery phrase,
- considering the use of configuration multisigespecially for larger amounts.
Updating the firmware alone will not change the security of a seed generated in the past.
Do users of other wallets have reasons to worry?
At this point, there is no indication that the problem affects other manufacturers. However, the community points out that the incident reminds us of one of the most important security rules of Bitcoin. Even the best hardware wallet cannot guarantee complete security if a cryptographic error occurs while creating private keys.
That’s why more and more experts recommend using configurations multisigin which several independent devices from different manufacturers are required to spend funds. This solution significantly reduces the risk of a single point of failure.
Is this the biggest incident of this type?
If it is confirmed that all the thefts result from a single vulnerability, this could be one of the largest known cases of exploiting a seed generation error by a hardware wallet.
The investigation is still ongoing, and researchers are analyzing subsequent addresses and trying to clearly determine the mechanism of the attack. However, one thing is certain – users of older devices Coldcard Mk3 they should check their firmware version as soon as possible and consider migrating funds to a new wallet generated with a new recovery phrase.