Skip to main content

Canadian Users Account for 25% of Coldcard Exploit Losses

Importance High

Canadian Bitcoin holders account for 25% of all attributable losses in the Coldcard hardware wallet exploit, which has stolen $116 million in total. Galaxy Research traced the attack to a March 2021 firmware update that introduced a flawed random number generator (RNG). The bug caused private keys to be generated with low entropy, silently failing without warning. An attacker exploited this five years later, sweeping $70 million from 1,200 wallets in 41 minutes.

Geographic distribution shows Australia as the second most affected (15-20%), followed by the US and Thailand (10-15% each). The breach also impacted Western Europe, Latin America, and African crypto hubs. The root cause was a configuration error (MICROPY_HW_ENABLE_RNG set to zero), which bypassed safety checks because the macro was defined even when set to 0, as explained by CertiK’s Natalie Newson.

In response, experts recommend removing fallback RNG providers and enforcing strict NIST FIPS 140-3 validation. For affected users, the remediation protocol is to generate a new offline seed phrase on a trusted hardware wallet, verify with a small transaction, then transfer remaining funds before attempting any firmware update on the compromised device.

The incident has sparked debate about self-custody. Critics argue that offline storage alone does not eliminate third-party risk. Nanak Nihal Khalsa of Human.tech noted that self-custody still outsources trust to hardware manufacturers. Industry consensus is shifting toward multi-vendor, multi-signature or threshold signature setups to avoid single points of failure. Newson concluded that no single compromised component should be able to move funds, urging adoption of setups spanning independent organizational and technological failure domains.

Source: https://news.bitcoin.com/security/canadian-users-account-for-25-of-coldcard-exploit-losses/