Coldcard Security Incident: 1359.882 BTC Stolen, Attacker Offers 10% CoinJoin Mix Service
August 3rd. In the security incident of Coldcard, a hardware wallet under the company Coinkite, the amount of Bitcoin stolen has now risen to approximately 1359.882 BTC. The Coldcard Sweep Watch dashboard indicates that the majority of the identified Bitcoin is still held in a few addresses controlled by the attacker.
On August 1st, the attacker's holding address received a transaction containing an OP_RETURN message. The message openly offered to provide "washing" services for Bitcoin at a 10% fee, KYC assistance, and assistance with withdrawing the proceeds of crime, along with a Telegram contact.
Coinkite has released an emergency firmware update to address the weak random number generation issue that led to the original vulnerability. The company stated that the new firmware only protects wallets created in the future and cannot repair the seeds generated in the affected versions.
Some users reported that after installing the update, their devices were stuck on error screens, unable to boot, or appeared bricked. The main devices affected were Mk4 and Q, with some Mk3 users also reporting similar issues. As of August 2nd, Coinkite has not publicly confirmed the existence of a widespread firmware flaw.