TLDR
A critical firmware flaw in Coldcard Bitcoin hardware wallets let an attacker reconstruct seeds and drain at least $38 million, with later analysis putting total losses near $70 million.
- A bug in Coldcards seed generation made recovery phrases partially predictable, enabling an offline brute-force attack that swept hundreds of wallets within minutes.
- The main risk applies to seeds created on specific Coldcard firmware since 2021; experts say updating alone is not enough and vulnerable seeds must be treated as compromised.
- The incident is shaking confidence in single-signature self-custody and may accelerate interest in multisig setups, diversified storage and regulated custodians, including spot Bitcoin ETFs.
Deep Dive
1. How The Drain Happened
Initial forensics found about 594 BTC, roughly $38 million, drained from around 500 Coldcard wallets in a 25?minute window on July 30, according to reports summarized by crypto.news.
Galaxy Research later traced 1,082.65 BTC, about $70.2 million, across 1,196 addresses in a 41?minute span, nearly doubling the original loss estimate and linking the sweep to a single coordinated operation mapped in on?chain analysis.
The attacker never touched the devices. Instead, a firmware bug reduced the randomness (entropy) in seed generation, making what should be astronomically unguessable recovery phrases computationally enumerable so private keys could be reconstructed offline.
Confidence: high because multiple independent research teams and Coldcards own statements converge on the same mechanism and loss range.
2. Affected Users And Concrete Risk
Coldcard maker Coinkite and independent researchers say the flaw appeared in firmware released from March 2021 onward. On Mk3 devices, hardware randomness was effectively disabled, dropping seed entropy from 128 bits to about 40 bits, as detailed in the bug explanation. Later models (Mk4, Mk5, Q) had improved but still insufficient entropy, around 72 bits before recent fixes.
Crucially, the problem is how the seed was originally created. Updating firmware removes the bug for future seeds but does not magically strengthen seeds that were already generated on vulnerable versions, a point emphasized in Coinkites advisory and reiterated by Galaxys estimate piece.
Security firms therefore classify any seed created on affected firmware without extra entropy (such as many dice rolls) or a strong BIP?39 passphrase as potentially compromised, even if funds have not yet been touched.
If you ever used a Coldcard to generate a seed during the vulnerable window, your risk depends on firmware version, how you added entropy, and whether you used strong passphrases or multisig.
3. Impact On Self?Custody And What To Watch
The episode is being cited as one of the largest failures of Bitcoin self?custody to date and is sparking debate over whether typical investors can safely manage keys alone, as covered in a Coindesk overview.
Industry voices are highlighting defense?in?depth: multisig wallets where no single compromised device can drain funds, independent entropy sources like physical dice, and diversifying holdings across storage types so one bug cannot wipe everything. At the same time, regulated custodians and spot Bitcoin ETFs may look more attractive to some users who prefer operational risk to be handled professionally.
Investigators are still tracking the attackers wallets and warning that more sweeps could occur against any remaining vulnerable seeds, while future attacks might not show the same clear on?chain fingerprint seen in the initial burst, according to Galaxys and Chainalysis commentary.
For larger BTC holders, the practical takeaway is to treat seed generation, redundancy and wallet architecture as core security design choices, not afterthoughts.
Conclusion
The Coldcard exploit shows that even highly regarded hardware wallets can harbor subtle bugs that turn cold storage into a soft target for determined attackers. A single entropy flaw at seed creation allowed tens of millions of dollars in Bitcoin to be drained without physical access, undermining trust in simple single?device setups.
Going forward, the most resilient arrangements will likely combine well?audited tools, stronger entropy practices and multisig or diversified custody, with careful monitoring of future advisories around wallet firmware and seed security.
