INCIDENT EVIDENCE GRAPH
Bitcoin Hardware Wallet COLDCARD Used Fake Random Numbers to Generate Seeds; Hacker Stole 594 Bitcoin in 15 Minutes
The Bitcoin hardware wallet COLDCARD has suffered a major security issue: a flaw in its random-number generation resulted in mnemonic phrases being generated from an extremely small range. After discovering the vulnerability, the hacker generated a large number of addresses on their own machine and matched them against on-chain data. The hacker then used private keys to directly transfer funds from active wallets that matched. On-chain data showed that the hacker emptied 500 wallets within just 15 minutes, taking 594 bitcoin, worth approximately CNY 254 million or USD 37.42 million.
- Victim: COLDCARD wallet users
- Actor: Hacker
- Method: Exploited flawed random-number generation to derive a small set of mnemonic phrases, matched generated addresses against on-chain data, and used private keys to transfer funds.