Coldcard Wallet Flaw Blamed on Faulty Code, Losses Near $120M
Security researchers have traced a major cryptocurrency theft to faulty randomness-generating code in the Coldcard hardware wallet, reportedly the work of Coinkite co-founder and CTO Peter Gray. Bitcoin developer James O'Beirne says he warned Coinkite about the defect back in May 2025, but the warning was reportedly dismissed.
The flaw, which affected how the wallet generated supposedly random values used to secure private keys, has now been connected to losses approaching $120 million in stolen Bitcoin. Weak or predictable randomness in cryptographic systems can allow attackers to guess or reconstruct private keys, effectively unlocking funds that should be secure.
This incident highlights a recurring problem in security: known vulnerabilities that go unaddressed can lead to significant financial damage down the line. While this case involves a specialised cryptocurrency wallet, it's a reminder for all businesses that vendor-reported security warnings should be taken seriously and investigated promptly, regardless of the source.