Bitcoin Theft from Coldcard Wallets Reveals Firmware Flaw and Licensing Changes

Bitcoin Theft from Coldcard Wallets Reveals Firmware Flaw and Licensing Changes

Attackers exploited a firmware flaw in Coldcard hardware wallets, generating wallet seeds with insufficient randomness and siphoning nearly $114 million from over 709 addresses. The vulnerability, introduced in a March 2021 code commit, remained undetected for more than five years despite being publicly available in open-source repositories. Coldcard’s shift from a GPL license in November 2020 to one incorporating the Commons Clause, which restricts modification and redistribution, has drawn scrutiny as a potential factor in limiting external oversight.

The flaw, which allowed attackers to predict wallet seeds, reportedly enabled the rapid draining of 500 wallets within 25 minutes during the initial breach. Researchers identified the issue after analysing Coldcard firmware builds, though the company’s co-founder, Rodolfo Novak, previously threatened legal action against independent scrutiny efforts. The change in licensing, which ended Coldcard’s open-source status, has been cited by some as fostering a culture of reduced transparency and collaboration.

Ben Perrin, host of BTC Sessions, acknowledged the broader industry challenges in balancing security with corporate interests, noting that “the hubris of some firms may come with a false sense of security.” Meanwhile, the WalletScrutiny project, which uncovered the flaw, faced criticism from Coldcard’s leadership, with Novak dismissing the researchers’ work as “PR terrorism.” The incident has intensified debates over the role of open-source licensing in cryptocurrency security.

Uncertainties remain about the extent to which Coldcard’s licensing changes influenced the flaw’s introduction or delayed its detection. Experts have also questioned whether the company’s approach to external feedback contributed to the prolonged vulnerability. The breach underscores ongoing tensions between proprietary control and community-driven security in the blockchain sector.


Written by Daniel Brooks
Security Desk

Share