TLDR
A Coldcard Bitcoin hardware wallet flaw has enabled hackers to drain about 1,367 BTC from roughly 4,600 addresses, with losses near 89 million dollars and the exploit still active.
- Galaxy Research tracks three attack waves tied to a Coldcard firmware bug that drained about 1,367 BTC from 4,585 addresses, with stolen funds still unmoved.
- The issue is specific to seeds generated on vulnerable Coldcard firmware, hitting many long term Bitcoin holders and sparking a wider self custody versus ETF debate.
- More vulnerable wallets could still be swept, and the main things to watch are vendor advisories, on chain movement of the stolen BTC, and further investigative updates.
Deep Dive
1. Scope And Attack Mechanics
Galaxy Research and multiple outlets report three attack waves exploiting Coldcard generated wallets, draining about 1,367 BTC worth roughly 88.6 to 89 million dollars across 4,585 addresses in total. This includes an initial high value sweep and later waves targeting smaller balances per address, confirming the attack is systematic rather than random.
The root cause is a firmware flaw introduced in March 2021 on certain Coldcard devices, where a predictable software random number generator replaced the intended hardware generator, sharply reducing seed entropy and making private keys guessable offline. Attackers appear to be brute forcing this weakened key space, possibly with AI assisted tooling, then programmatically sweeping vulnerable wallets.
So far, reports indicate the stolen Bitcoin remains parked in attacker controlled addresses and has not yet been laundered, which makes the theft visible on chain but also suggests the operation is not finished.
2. Who Is At Risk And Why It Matters
The incident is tied to seeds created on specific Coldcard firmware versions, not to Bitcoin itself or to all hardware wallets in general. Analysis shows the affected coins were dormant for years on average, meaning many victims were long term self custody users who believed they were highly secure.
Because the flaw undermines a key self custody assumption, some users are moving funds back to exchanges or other custodial solutions, while commentators argue that it is a failure of one wallet implementation rather than of self custody as a concept. At the same time, ETF advocates are using the event to highlight institutional custody as an alternative for users who are not comfortable managing seed risks.
If your Bitcoin security model relies on a single hardware wallet or on default seed generation, this event is a reminder to understand your devices firmware history and randomness model, not just its marketing.
3. What To Watch Next
Galaxys work suggests the vulnerable key space is finite but not yet fully exhausted, so additional sweeps of remaining high and mid value wallets are possible until all exposed seeds are either drained or migrated. Vendor advisories from Coinkite and ongoing research updates will be key signals for when risk is meaningfully reduced.
On chain, analysts are monitoring whether the attacker starts moving or mixing the stolen BTC, which would shift the story from key compromise to laundering and enforcement. Regulators and law enforcement in affected jurisdictions are already receiving reports from victims, which could eventually translate into clearer public guidance on hardware wallet standards.
For Bitcoin users, the practical focus over the next days and weeks is on checking whether any wallet setup might rely on the flawed firmware and then following the manufacturers latest security instructions, while watching on chain flows for signs that the exploit phase is ending and a laundering phase begins.
Conclusion
The Coldcard cold wallet exploit is a targeted failure of seed generation that has escalated into one of the largest self custody incidents in Bitcoin history, draining long held coins from thousands of addresses. It does not compromise Bitcoin itself, but it does expose how subtle implementation bugs in hardware wallets can turn offline security into a single point of failure, and it is already reshaping the conversation around how everyday users should balance self custody, diversified wallet setups, and institutional options.
