Cold Card Firmware Vulnerability Leads to $130 Million Theft
A firmware vulnerability in Cold Card devices allowed attackers to exploit the hardware RNG. The incident has resulted in a reported loss of $130 million, with most funds remaining untouched.
A firmware vulnerability in Cold Card devices enabled attackers to route the hardware random number generator (RNG) to a guessable software fallback. This flaw allowed them to brute-force the seeds offline without the need for phishing or malware. As a result, a significant theft has occurred, with $130 million reported stolen so far and at least 15 attackers involved in the incident.
Despite the scale of the theft, most of the stolen funds remain untouched, indicating that the attackers may not have fully liquidated their gains. The specific blockchain involved in this incident is not stated, which limits the ability to trace the stolen assets directly. The lack of information on the chain also means that the on-chain record details are not available for analysis.
No individuals have been apprehended in connection with this incident, and the ongoing nature of the investigation remains unclear. The situation highlights the potential risks associated with firmware vulnerabilities in hardware wallets.