The critical vulnerability involved a software error that bypassed the devices' secure randomness generator, making the supposedly unique "seed phrases"—the master passwords used to generate private keys—predictable and easy for computers to guess.
This exploit is significant because it bypassed the primary security benefit of "cold storage," which is keeping private keys entirely offline and unreachable by hackers.
By exploiting the flawed firmware, attackers did not need to touch or infect the physical wallets; instead, they used their own hardware to calculate and test billions of possible key combinations against the public blockchain.
Security experts warn that this systematic approach allows attackers to refine their search and potentially launch further waves of thefts against any funds remaining in vulnerable wallets.
While Coinkite, the manufacturer of Coldcard, initially suggested only older models were at risk, reports from security firms indicate that newer versions, including the Mk4 and Q models, may also be affected.
Users currently have no reliable way to verify if their specific seed phrases were generated using the faulty firmware, leading investigators to advise moving funds to new, secure locations.
Authorities are now following leads provided by Block researchers, who traced the attacker’s activity through logs from a blockchain data provider used to identify the target addresses.