Need help? Support
BITCOIN
Tether Dominance USDT.D

Coinkite warns Coldcard users after $38M loss

Published 563 words 3 min read

TLDR

A long?standing firmware bug in Coinkites Coldcard hardware wallets allowed an attacker to steal at least $38 million in Bitcoin, triggering an urgent warning to affected users.

  1. An exploit of a seed generation flaw drained 594 BTC, initially valued around $38 million, from roughly 500 Coldcard wallets within minutes, with later analysis pushing total losses above $70 million.
  2. Coinkites advisory says certain Coldcard models and firmware versions created weak recovery seeds; simply updating firmware is not enough and vulnerable users must migrate to new, securely generated seeds.
  3. The incident shows that even reputable hardware wallets can harbor critical bugs, reinforcing the need for multi?layer security, diversified storage, and careful vigilance around self custody setups.

Deep Dive

1. Exploit And Losses

Reports detail a coordinated sweep where an attacker exploited a firmware bug in Coldcard devices, allowing predictable recovery seeds and offline reconstruction of private keys, without touching the hardware itself. Coverage of the firmware bug describes 594 BTC, about $38 million, drained from around 500 wallets in roughly 25 minutes.

On chain tracing by Galaxy Research and others later expanded the scope to about 1,082.65 BTC, near $70 million, across more than 1,100 addresses, with some estimates now exceeding $75 million as more affected wallets are identified. The stolen coins have largely remained in a small set of attacker addresses, under close public scrutiny.

2. Who Is Affected And Guidance

The vulnerability relates to how certain Coldcard firmware versions (starting in March 2021) generated seeds, falling back to a software random number source instead of the intended hardware generator. This reduced entropy the randomness that makes a seed hard to guess from the usual 128 bits to roughly 40 bits on some devices, making brute force attacks feasible.

Coinkites warning focuses on Coldcard Mk3 and some newer models whose seeds were created on affected firmware. Critically, updating to patched firmware protects only seeds generated after the fix; any seed created while the bug was present stays weak until funds are moved to a brand?new seed. Users who added strong extra randomness, such as sufficient dice rolls or a robust BIP?39 passphrase, are considered much safer but are still urged to review their setup carefully.

3. Lessons For Self Custody

The breach undermines the assumption that hardware wallets are near?perfect defenses and shows that implementation mistakes can linger for years in open source code before attackers strike. Commentators like CZ have urged holders to diversify across multiple wallets and security models rather than rely on a single device type, while acknowledging that added complexity creates new human?error risks.

For large Bitcoin holdings, security experts are highlighting defense?in?depth practices such as multisignature arrangements, independent entropy sources when generating seeds, and active monitoring of vendor advisories for firmware and design issues.

What this means

If you rely on any hardware wallet, treat vendor security notices as action?forcing events, verify how and when your seed was generated, and consider layered setups so that no single bug can end your entire stack.

Conclusion

Coinkites Coldcard incident is a stark example of how a subtle firmware bug can translate into tens of millions of dollars in losses, even for long?trusted hardware wallets. The immediate priority is for affected Coldcard users to understand whether their seeds were generated on vulnerable firmware and, if so, to migrate carefully. Longer term, the episode strengthens the case for diversified, multi?layer self custody and for treating wallet security as an ongoing process rather than a one?time purchase.

Educational information only. Crypto markets are volatile and this is not financial advice.


Top