TLDR
A critical randomness flaw in Coldcard Bitcoin hardware wallets enabled an attacker to brute-force seeds and steal roughly 594 BTC, worth around 38 to 40 million dollars, from hundreds of wallets.
- The exploit targeted weak key generation on older Coldcard firmware, draining about 594 BTC from around 500 single-signature wallets in roughly 25 minutes.
- Seeds generated on specific Mk3 and some other firmware versions are at risk, while setups with strong BIP-39 passphrases or extra entropy appear significantly safer.
- The incident is denting confidence in self-custody and hardware wallets, with experts expecting more audits and possibly greater use of custodial services and Bitcoin ETFs.
Deep Dive
1. Exploit Scale And Mechanics
Reports show about 594 BTC, roughly 38 million dollars, were swept from around 500 single-signature wallets between 01:31 and 01:56 UTC in a coordinated attack linked to Coldcard firmware flaws. The theft moved over 1,300 UTXOs and consolidated around 562 BTC into a single address that has not yet moved, according to detailed on-chain analyses and reporting such as Coindesks coverage of the Coldcard wallet flaw draining 594 BTC.
The bug disabled the hardware random number generator and fell back to a predictable software source seeded by device serial numbers and clocks, making wallet seeds mathematically guessable. Later analysis from Galaxy Research suggests total losses may already exceed 1,000 BTC, around 70 million dollars, for a broader set of drained addresses linked to the same vulnerability, as described in their Bitcoin losses linked to Coldcard vulnerability.
2. Who Is Actually At Risk
Coinkites advisory warns that seeds generated on Coldcard Mk3 devices running firmware from version 4.0.1 through 5.0.3 are critically exposed, and older firmware on Mk4, Mk5, and Q devices also had reduced entropy before emergency fixes. Their blog guidance urges users with seeds created on affected firmware to treat those seeds as compromised and migrate funds to new seeds generated on patched hardware, backed up and tested first, as outlined in the Coldcard Mk3 seed-generation warning.
Multiple incident summaries note that wallets protected with a strong BIP-39 passphrase or generated with many physical dice rolls had sufficient extra randomness to resist the known attack pattern. Multisignature setups help only if none of the keys were created on compromised devices, because the flaw occurs at seed creation and is not fixed by importing that seed elsewhere.
If you have ever generated a Coldcard seed on older firmware, it is important to check the exact model and version used, then follow the vendors latest migration guidance rather than assuming cold storage is automatically safe.
3. Broader Impact On Bitcoin Self-Custody
Despite the size of the theft, early market coverage notes that Bitcoins price has shown little immediate reaction, suggesting the drain is large for individuals but still small relative to total market cap and daily flows. Coindesks broader analysis of how Coldcards 38 million dollar exploit shakes faith in self-custody highlights growing concern that managing private keys on consumer devices carries non-trivial engineering risk.
Coinkite and several reports also raise an AI angle, suggesting the attacker may have used AI to review old open-source firmware and spot subtle randomness bugs that prior human and AI audits missed, as explored in Decrypts piece on Bitcoin drained by a Coldcard key flaw AI likely found. That strengthens the case for more independent audits and diversified custody approaches rather than blind trust in any single wallet brand.
Conclusion
A hidden firmware randomness bug turned some Coldcard-generated seeds from effectively unguessable into solvable puzzles, allowing one attacker to drain tens of millions of dollars in Bitcoin from hundreds of long-held wallets. The direct impact is concentrated on users who created seeds on specific older firmware without extra passphrases or entropy, but the reputational impact reaches the wider hardware wallet ecosystem. For crypto users, this incident is a reminder that self-custody remains powerful yet unforgiving, and that careful attention to seed generation, firmware, and vendor advisories is just as important as keeping keys offline.
