TLDR
A critical Coldcard hardware wallet vulnerability has allowed attackers to drain around $88 million in Bitcoin, and the exploit is still active.
- Galaxy Research now tracks about 1,367 BTC, roughly $88.6 million, stolen from 4,585 addresses across three attack waves linked to Coldcard firmware flaws.
- The root cause is a March 2021 seed-generation bug on specific Coldcard models, forcing vulnerable users into urgent seed migration and reigniting debate over self-custody versus ETF or exchange custody.
- Bitcoin holders are moving coins back to exchanges, regulators and lawyers are circling Coinkite, and the key risk is further waves and revised loss estimates as investigations continue.
Deep Dive
1. Scale Of The Losses
Galaxy Research estimates that 1,367.05 BTC, about $88.6 million, has been drained from 4,585 addresses in three coordinated attack waves tied to Coldcard wallets created with flawed firmware, with the latest wave targeting smaller balances and newer addresses tracked on chain.
Reports from multiple outlets including Decrypt and CryptoSlate describe the exploit as ongoing, with stolen coins remaining in attacker-controlled wallets and on-chain patterns consistent with one or a small number of highly systematic operators analyzed by Galaxy.
Legal commentary suggests users have lost over 1,300 BTC and are preparing potential class actions against Coinkite, the maker of Coldcard, over the wallet bug that enabled the theft outlined in this legal analysis.
Confidence: high because independent research teams and several major media reports converge on similar loss estimates and timelines.
2. How The Exploit Works And Who Is At Risk
The vulnerability traces to a March 2021 firmware integration error where affected Coldcard devices used a predictable software random-number fallback instead of the intended hardware random-number generator to create seed phrases, sharply reducing entropy and making the private keys brute-forceable offline described in detail here.
Crypto.news and Galaxy Research specify that Mk2 and Mk3 devices running firmware 4.0.1 to 4.1.9, Mk4 and Mk5 units before version 5.6.0, and Coldcard Q before 1.5.0Q are affected, while Mk1, TAPSIGNER, OPENDIME and SATSCARD are not listed in Coinkites advisory summary.
Coinkite has shipped patched firmware, but all sources stress that updating does not fix seeds created under the flawed versions, so users need new seeds on secure firmware and to migrate funds away from any wallets that relied solely on the buggy randomness as security guidance explains.
if a Coldcard wallets original seed was generated on an affected firmware without strong extra entropy, that setup could eventually be swept even if the device has never touched the internet.
3. Impact On Bitcoin Flows And Self-Custody
Unlike past exchange failures, this incident is pushing many smaller Bitcoin holders to move coins from hardware wallets back to exchanges, with one analysis citing daily deposits under 10 BTC spiking to 7,300 BTC and net inflows over 11,000 BTC to major venues such as Binance and Kraken documented by on-chain flow data.
CryptoSlate notes that wallet migrations have moved over 77,000 older BTC and are distorting standard on-chain signals that usually look like selling, even though much of the flow is protective reshuffling rather than outright liquidation highlighted in this market impact review.
Commentators from Galaxy, Binance and ETF analysts argue this episode will likely accelerate pressure on hardware wallet makers to prove entropy and security, while also strengthening narratives around diversified custody, multi-wallet setups, and regulated ETF-style products for less technical users summarized in a recent industry roundup.
crypto users may increasingly weigh self-custodys control benefits against firmware and key-generation risks, watching closely how Coldcard and peers respond with audits, fixes and compensation policies.
Conclusion
The Coldcard exploit is a rare case where a hardware wallet bug, not an exchange collapse, has driven tens of thousands of BTC into motion and inflicted roughly $88 million in direct losses.
For now Bitcoins protocol remains intact and losses are confined to specific flawed setups, but the incident exposes how fragile trust can be when seed generation fails and will likely reshape standards for wallet randomness, auditing and user education across the industry.
