Someone always holds your Bitcoin keys — make sure it’s you

A Coldcard flaw produced weak seed randomness allowing attackers to derive private keys and drain wallets; Trezor urged users to verify firmware and retain control of keys.

A flaw in Coldcard hardware wallet software produced weak seed randomness when some devices were initialized, allowing attackers to derive private keys and drain funds from affected wallets. The issue emerged in recent days as owners reported unauthorized withdrawals from wallets created with predictable seeds.

The vulnerability was specific to how some Coldcard devices generated randomness during setup. Devices initialized with insufficient entropy created recoverable seeds that attackers matched to private keys. Affected owners reported losses after attackers recreated those keys and moved funds.

Trezor responded by urging users to keep control of their private keys and to verify the firmware and hardware of any wallet they use. The company pointed to open-source firmware and public device designs as tools that allow independent inspection. Trezor used the phrase “Do not trust us. Verify us.” to describe its transparency approach and noted its bug bounty program as an incentive for outside researchers to examine code.

The company provided practical guidance for custody decisions. It recommended verifying device firmware and provenance, writing down seeds correctly and storing them securely. For users managing large amounts, Trezor highlighted multisignature setups, which require several independent keys to authorize transactions; the company has supported multisig since 2014. At the same time, it warned that multisig adds operational complexity, including correct construction, backup and restoration challenges.

Trezor cautioned against moving coins en masse to exchanges or other custodial services in response to the incident. The company stated that custodial arrangements replace the technical risk of a device flaw with counterparty risk, including potential insolvency or theft at the custodian.

Industry participants report that the Coldcard incident has prompted deeper audits of wallet code across manufacturers. Trezor said it has seen some users migrate from other vendors following the incident and that it will continue to support incoming users under its existing security model.

The material on GNcrypto is intended solely for informational use and must not be regarded as financial advice. We make every effort to keep the content accurate and current, but we cannot warrant its precision, completeness, or reliability. GNcrypto does not take responsibility for any mistakes, omissions, or financial losses resulting from reliance on this information. Any actions you take based on this content are done at your own risk. Always conduct independent research and seek guidance from a qualified specialist. For further details, please review our Terms, Privacy Policy and Disclaimers.

Articles by this author