Coldcard flaw exposed $116M self-custody risk: Gray
The Coldcard seed-generation failure has exposed about $116 million in Bitcoin to theft while renewing questions about how users verify the security of self-custody tools, according to TEXITcoin founder Bobby Gray. SummaryAttackers have reportedly drained about 1,816 BTC worth $116 millionfrom more than 5,200 addresses.A firmware error left some Coldcard seeds with about 40 bits of entropyinstead of 128 bits.Gray said users who added independent dice-generated entropywere not affected by the reported attacks.Coinkite has released patched firmware, but existing vulnerable seeds require a complete wallet migration. Bobby Gray, founder of TEXITcoin, told crypto.news that Coldcard users suffered losses because they trusted the hardware wallet to generate secure seed phrases without independently checking the source of randomness. “Coldcard sat on a broken seed generator for five years, and it still cost people $116 million,” Gray said. “Some of these wallets were generating seeds with as little as 40 bits of entropy instead of the 128 they promised.” Gray said the lower entropy turned recovery phrases designed to resist brute-force attacks into targets that determined attackers could search without gaining physical access to the devices. You might also like: Coldcard temporarily halts customer data deletion over July exploit Coldcard seed flaw weakened wallet security Coldcard is a Bitcoin-only hardware wallet made