Coldcard exploit triggers mempool wars across Bitcoin
- Coldcard firmware flaws enabled automated drains targeting over $130 million in Bitcoin holdings.
- Developers used private mining relays like Marathon's Slipstream to protect 5,600 Bitcoin from mempool snipers.
- Machine-speed AI probes forced Lightning swap providers offline and shattered single-vendor self-custody norms.
A five-year-old firmware error has escalated into a full-scale automated war across the Bitcoin network. What began as a catastrophic key drain on Coldcard hardware wallets has turned into a high-stakes battle inside the mempool, where white-hat defenders and automated scripts fight over exposed unspent outputs.
The core vulnerability traces back to a March 2021 firmware commit. A preprocessor macro error in the C code caused Coldcard devices to silently bypass their hardware random number generator during key creation. Instead of failing closed, the devices defaulted to predictable software fallbacks with as little as 32 bits of entropy, leaving seeds vulnerable to basic laptop brute-forcing.
Cryptographic signatures recently linked the fatal commit to the personal GPG key of Coinkite chief technology officer Peter Gray. Security researcher James O'Byrne identified 58 signed commits under a GitHub alias that pushed the broken entropy code directly to production without peer review. The discovery shattered user trust in single-vendor code reviews and hardware air-gaps.
Artificial intelligence drastically accelerated both the discovery and execution of the exploit. While malicious actors used unrestricted models to scan repositories and grind through weak key spaces, defensive researchers faced safety guardrails on domestic platforms. Galaxy Research head Alex Thorn noted that analyzing public blockchain data triggered safety downgrades on frontier models, forcing security teams to use open-source alternatives.
The machine-speed attack vectors quickly spilled beyond individual wallet balances. Machine-driven probes overwhelmed non-custodial Lightning infrastructure, forcing services like Boltz Exchange and Zeus Lightning to pause operations indefinitely. Open-source maintainers acknowledged that small developer teams could no longer patch newly uncovered vulnerabilities as fast as automated AI agents identified them.
For compromised holders, broadcasting standard recovery transactions became a hazard. Attackers monitoring the public mempool used Replace-By-Fee bidding wars to front-run transfer attempts and divert funds in real time. Simultaneously, the exposed key space retroactively de-anonymized historical CoinJoin rounds, shrinking the anonymity set for innocent participants who mixed coins alongside flawed Coldcard seeds.
To survive the mempool predator zone, distressed holders turned to private transaction relays. Mempool researcher Orange Surf tracked over 5,600 Bitcoin routed through Marathon's Slipstream service since the exploit surfaced. By submitting signed transactions directly to miners rather than broadcasting them publicly, multisig signers prevented front-running scripts from intercepting their remaining funds.
The fallout has permanently altered hardware custody standards across the industry. Prominent ecosystem figures like Marty Bent and Matt Odell have abandoned single-vendor recommendations, urging holders toward multi-signature quorums with distinct hardware vendors. Trust in single-device sovereignty is broken, replaced by an era where every line of open-source firmware must assume perpetual machine attack.
Source Intelligence
- Deep dive into what was said in the episodes
CATASTROPHIC COLDCARD BUG • Aug 3
- The bug, which existed for five years, appears to have been recently identified with assistance from AI, possibly through OpenAI's Cypher program utilized by Rob Hamilton's team for auditing Bitcoin projects.
Also discussed on this episode: (12)
Custody (6)
- A critical vulnerability in Coldcard hardware wallets (versions 4.0.1 and later, or any model after 4.0.0) compromises private keys due to a faulty random number generator.
- The catastrophic Coldcard bug, introduced in March 2021, compromises seeds generated on any device after that date unless sufficient dice roll entropy (over 100 rolls) or a passphrase was used.
- Hosts advise all Coldcard users to immediately move their funds off the devices and to cease using the product entirely, regardless of previous protective measures like passphrases or multisig.
- The hosts had previously conducted Coldcard workshops since December 2019 at Chaincode Labs with figures like Evan Kaludis and James O'Byrne, demonstrating features like dice rolls and passphrases.
- Hosts concede to complacency, having placed too much trust in CoinKite's NVK and Peter; they now believe the concept of a "magic bullet" beginner-friendly solution for high-value self-custody is dead.
- The hosts will now refrain from directly recommending specific custody solutions, instead laying out options and emphasizing multi-vendor multisig and robust passphrases as critical for long-term secure Bitcoin storage.
Media (2)
- The hosts express deep regret and take accountability for recommending Coldcard for seven years, admitting their past confidence was misplaced despite consistently advocating "don't trust, verify."
- The Coldcard vulnerability was publicly disclosed on August 3, 2023, at Bitcoin block height 960885, prompting hosts to release this podcast immediately to maximize user notification efforts.
Safety (4)
- The Bitcoin community has rallied to assist affected users, with Rob Hamilton (@Roboneham on X) publishing an extensive guide detailing Coldcard vulnerabilities, migration options, and recovery steps.
- Attackers are actively brute-forcing compromised Coldcard seeds using GPUs, while authorities are investigating an attacker who reportedly pinged a centralized API provider to look up vulnerable addresses.
- The hosts clarify the vulnerability is entirely CoinKite's responsibility, stating their firm 1031 is a minority investor (under 10%) with NVK and Peter maintaining majority ownership and control.
- Users are strongly advised not to update Coldcard firmware, as new releases may brick devices; instead, the immediate priority should be transferring all funds off the compromised hardware.
