Coldcard Wallet Flaw Linked to $100 Million in Bitcoin Losses
Coldcard, a popular hardware wallet used to store Bitcoin private keys, has been linked to a flaw involving how it generates the random data—known as entropy—used to create cryptographic keys. According to reports, this weakness has been exploited to steal more than $100 million worth of Bitcoin from affected users.
At the heart of the issue is a long-running debate in the crypto security community about whether supplementary methods for generating entropy, such as rolling dice, can be trusted to strengthen key security or whether they introduce new risks if not implemented correctly. Weak or predictable entropy can make it possible for attackers to guess or reconstruct private keys, giving them direct access to a victim's funds.
While this incident centres on a niche piece of hardware, it highlights a broader lesson for any business handling digital assets or sensitive cryptographic material: the strength of your security is only as good as the randomness and processes behind your key generation. Businesses using hardware wallets or similar devices for cryptocurrency holdings should stay alert to vendor security advisories and firmware updates.