Need help? Support
BITCOIN
Tether Dominance USDT.D

Wallet bug drains $88M in BTC

Published 641 words 3 min read

TLDR

A critical bug in Coldcard Bitcoin hardware wallets has allowed attackers to drain about $88 million in BTC from vulnerable addresses, shaking confidence in self custody.

  1. Coldcard firmware seeded some wallets with weak randomness, letting attackers reconstruct private keys and steal around 1,367 BTC across thousands of addresses.
  2. The flaw mainly affects seeds created since 2021, triggering huge movements of older BTC that distort on chain metrics and amplify bearish sentiment.
  3. Impacted users now face complex decisions on migrating seeds, pursuing legal action against Coinkite, and weighing self custody against institutional ETF-style custody.

Deep Dive

1. Scale And Mechanics Of The Bug

Reports from Galaxy Research and others say three attack waves have drained roughly 1,367 BTC, about $8889 million, from Coldcard-generated addresses, and the sweeps are still ongoing. The issue stems from a firmware build error that routed seed phrase generation through a deterministic software fallback rather than the intended hardware random-number generator, making some seeds far easier to guess.

Analyses suggest affected wallets are largely single-signature and often long dormant, with an average of more than three years without movement before they were emptied, according to the latest Coldcard exploit losses estimates. Bitcoins protocol itself is not broken; attackers are simply creating valid transactions with compromised private keys.

Confidence: high, based on multiple independent on chain analyses and Coinkites acknowledged firmware flaw.

2. Distortion In On Chain And Market Signals

Because the flaw threatens older Coldcard-held coins, many holders have rushed to migrate funds, moving more than 77,000 BTC and driving the largest wave of old coin activity since the FTX collapse. This spike in address activity, exchange deposits and small output movements is making standard on chain indicators look like capitulation or large-scale selling, even when much of the flow is defensive repositioning rather than exits.

One analysis finds that the Coldcard crisis has completely distorts market signals, as metrics like Coin Days Destroyed and long-term holder supply change are now heavily influenced by bug-driven moves rather than organic sentiment-driven trades, per this market impact review. This noise can mislead traders and analysts who rely heavily on those series.

What this means

Short term, treat on chain selling and long term holder metrics around this event with caution, since much of the movement reflects security responses rather than a clean change in conviction.

Coinkite has shipped emergency firmware fixes and is urging users with potentially affected seeds to create new, high-entropy seed phrases and move funds, noting that simply updating firmware does not secure seeds generated with the flawed randomness path. Security researchers highlight that alternative methods, like dice-based entropy or strong passphrases, can mitigate risk, but they do not retroactively fix already compromised seeds.

Victims and lawyers are exploring product-liability and negligence theories against Coinkite, with some arguing that the firm bears responsibility and others warning that hardware wallet makers may have limited formal obligations, as outlined in this class action threat coverage. At the same time, ETF and institutional-custody advocates are using the incident as evidence that some users may prefer professionally managed custody over direct key management, accepting different counterparty and operational risks.

What this means

The episode reinforces that self custody is powerful but not risk free, and that diversification across custody methods and careful attention to wallet security practices can matter as much as price levels.

Conclusion

The Coldcard wallet bug is a reminder that Bitcoins cryptography can remain intact while wallet software or firmware introduces catastrophic vulnerabilities. The resulting $88 million drain is reshaping both on chain activity and the custody debate, pushing users to reassess how they secure large BTC balances and how much they trust small wallet vendors versus institutional custodians. Over the next weeks, the key signals will be any expansion in the loss tally, Coinkites technical and legal responses, and whether the market can distinguish genuine selling from defensive coin movements driven purely by security concerns.

Educational information only. Crypto markets are volatile and this is not financial advice.


Top