Need help? Support
BITCOIN
Tether Dominance USDT.D

Coldcard wallet flaw drains $70M BTC

Published 652 words 3 min read

TLDR

A long hidden Coldcard hardware wallet flaw let an attacker reproduce Bitcoin seeds offline and drain around 70 million dollars from more than 1,000 wallets in under an hour.

  1. A 2021 firmware bug weakened seed randomness, allowing keys to be brute forced and at least 1,082 BTC to be swept from roughly 1,196 Coldcard wallets.
  2. Wallets whose seeds came from vulnerable firmware without extra entropy or strong passphrases were most at risk, while dice based seeds, multisig and unaffected devices largely survived.
  3. Users and industry now face a self custody confidence shock, ongoing follow up sweeps, and urgent migration to safer setups on patched firmware.

Confidence: high, based on aligned reports from Coinkite, Galaxy Research and multiple independent news outlets.

Deep Dive

1. How The Coldcard Flaw Drained Millions

Investigators say the attack targeted Coldcard devices whose firmware, first released in March 2021, accidentally disabled the hardware random number generator and fell back to predictable software based randomness using serial numbers and clock data. That cut seed entropy from an intended 128 bits to roughly 40 to 72 bits, making it computationally feasible to enumerate candidate seeds and reconstruct private keys offline.

Galaxy Research and others traced a coordinated sweep in which more than 1,000 bitcoin, worth about 70 million dollars, were drained from 1,196 wallets in roughly 41 minutes, with identical high fees and no change outputs indicating automated withdrawals from precomputed keys, as described in Coindesks analysis of bitcoin cold wallet losses. A later update flagged additional attack waves, bringing losses near 89 million dollars across about 4,585 addresses.

Coinkite, the maker of Coldcard, has acknowledged the bug, tied it to a five year old software configuration error, and confirmed that updating firmware cannot repair seeds that were already generated on vulnerable versions.

2. Who Was Hit And Who Was Safer

Reports from Bitcoin.com and Galaxy Research explain that the highest risk group were Coldcard Mk3, Mk4, Mk5 and Q wallets whose recovery phrases were created on affected firmware, without extra human added entropy or a strong BIP 39 passphrase. Many of these wallets belonged to long term holders and had been dormant for years before being emptied.

Users who rolled physical dice for seed generation, applied unique passphrases, or placed Coldcard keys inside multisig setups had much more effective entropy and were generally missed by the attacker. Other Coinkite products like Opendime and Satscard, plus competing hardware wallets from Ledger and Trezor, are reported as unaffected due to different randomness implementations.

Santiment and other analytics firms note that fear around self custody has spiked, but bitcoin price itself has moved only modestly, suggesting sentiment damage exceeds immediate market impact.

What this means

The flaw sits in how some Coldcard seeds were created, not in the Bitcoin network, so risk clusters around specific devices, firmware versions and setup choices.

3. What To Watch Next

Coinkite has shipped emergency firmware updates and urges users to generate entirely new seeds on fixed versions and then migrate funds, warning that simply updating a device leaves old seeds exposed, as highlighted in Bitcoin.coms Coldcard exploit explainer. Galaxy Research has identified several large consolidation wallets holding the stolen BTC, and future movements from those addresses will be closely watched by law enforcement and analytics firms.

A third wave of smaller balance sweeps shows the attacker continues to scan for vulnerable keys, and Coinkite has speculated that AI assisted code review may have helped find the flaw, though this remains unproven and critics frame it as a human engineering oversight. Industry discussions now focus on stronger entropy testing, deeper audits for hardware wallets, and diversified custody setups to avoid single points of failure.

Conclusion

The Coldcard incident demonstrates that even respected hardware wallets can harbor latent cryptographic bugs that convert cold storage into a vulnerability once seeds are generated incorrectly. For crypto users, the key lesson is that self custody security depends not only on owning a device, but on how keys are created, protected and diversified, and on staying alert to firmware advisories and emerging attack patterns.

Educational information only. Crypto markets are volatile and this is not financial advice.


Top