TLDR
A serious bug in Coldcard Bitcoin hardware wallets weakened seed generation, allowing attackers to brute-force private keys and drain tens of millions of dollars from hundreds of wallets.
- A firmware flaw in Coldcards random number generation let an attacker sweep at least 594 BTC from around 500 single-signature wallets, with some analyses estimating up to about 1,083 BTC affected.
- The risk is concentrated in seeds created on specific Coldcard firmware versions since 2021, especially where users did not add strong passphrases, dice entropy, or multisig protection.
- Self-custody practices are under scrutiny; users should verify whether their seeds are in the affected cohort and follow official Coinkite and Block guidance, while broader Bitcoin markets remain relatively calm.
Deep Dive
1. What Happened Technically
Reports from multiple sources describe a flaw in how certain Coldcard devices generated wallet seeds. Instead of using a true hardware random number generator, vulnerable firmware fell back to predictable device data like serial numbers and clocks, dramatically reducing entropy and making seeds guessable.
Analyses from Block and Galaxy Digital indicate an automated exploit drained roughly 594 BTC, about 38 million dollars, from around 500 wallets in 25 to 41 minutes, with broader tracing linking up to 1,196 addresses and about 1,083 BTC, nearly 70 million dollars, to the same bugged seed pattern. These findings are summarized in detailed incident writeups such as The Coldcard Exploit Explained and Galaxys loss analysis.
A hardware wallet that was supposed to keep keys unguessable effectively turned some seeds into puzzles powerful computers could solve.
2. Who Is At Risk And Who Is Safer
Blocks disclosure and follow up articles note that multiple Coldcard generations are affected: Mk2 and Mk3 devices where a coding error replaced proper randomness, and newer Mk4, Q, and Mk5 devices that added only limited extra entropy before recent fixes. Coverage like Bitcoin Wallets at Risk and Coldcard Security Notice highlight firmware ranges and model specifics.
Risk is highest for users who generated single-signature seeds on vulnerable firmware without additional protections. Strong BIP?39 passphrases, substantial user-supplied dice rolls, and robust multisig setups significantly reduce exposure, because they add independent randomness or require multiple keys to move funds. Importing an already compromised seed into another wallet does not fix the problem, as the weakness is baked into how the seed was originally created.
The key question is not do I own a Coldcard, but how and when was my seed generated, and did I add strong extra entropy.
3. Impact On Self-Custody And What To Watch
Coverage from outlets such as CoinDesks incident analysis notes that Bitcoins market price barely reacted, but confidence in hardware wallets and simple single-signature self-custody took a hit. Commentators argue this may push some holders toward regulated custodians or spot Bitcoin ETFs in search of perceived operational safety.
Coinkite has released fixed firmware versions and publicly accepted responsibility, but all guidance stresses that updating software alone does not secure old, weak seeds. The practical mitigation is to follow official instructions to generate new, high-entropy recovery phrases on patched devices and migrate funds carefully. For the wider ecosystem, this incident will likely drive more emphasis on verifiable randomness tests, independent firmware review, and default use of strong passphrases or multisig.
For crypto users, this is a reminder that self-custody is powerful but unforgiving, and that wallet choice, seed generation method, and firmware hygiene matter as much as price action.
Conclusion
A long-standing randomness bug in Coldcard firmware turned a subset of offline, secure Bitcoin wallets into targets that an attacker could systematically crack, draining tens of millions of dollars without phishing or key theft.
The exploit has not destabilized Bitcoins price, but it has exposed weaknesses in hardware wallet auditing and the risks of simple single-signature setups. Going forward, the most important signals to watch are updated guidance from Coinkite and Block, adoption of stronger seed practices like passphrases and multisig, and whether trust shifts toward custodial or ETF-based exposure as users reassess their self-custody risk.
