TLDR
A bug in certain Coldcard hardware wallets has enabled remote attackers to drain over 1,000 BTC from users in multiple coordinated waves.
- Researchers estimate roughly 1,367 BTC, about $8889 million, has been stolen from Coldcard-generated wallets across several attack waves.
- The root cause is a March 2021 firmware flaw that generated weak, partially predictable seed phrases, making private keys brute-forceable without touching the device.
- The incident is reshaping self-custody behavior, triggering flows back to exchanges and likely legal action against Coinkite, while attacks may still be ongoing for vulnerable wallets.
Deep Dive
1. Scale Of The Losses
Galaxy Research and multiple media reports now tie the exploit to about 1,367 BTC drained from 4,585 addresses, worth roughly $8889 million at recent prices, across three to four waves of attacks. Coverage from outlets such as Cryptoslate and Decrypt describes clustered sweeps where hundreds of BTC were emptied in minutes, including a single wave that stole over 1,082 BTC in roughly 41 minutes from long-dormant wallets.Coldcards 89M wallet bug
The stolen coins largely remain in attacker-controlled addresses and have not been widely laundered, though some on-chain messages even advertise laundering services, underscoring the brazenness of the incident.Coldcard hacker gets brazen
This is one of the largest hardware wallet failures seen in Bitcoin, with concentrated, traceable losses rather than quiet drip theft.
2. How The Bug Works And Who Is At Risk
Reports indicate that a March 2021 Coldcard firmware build sometimes fell back to a software random number generator when creating seed phrases, instead of the secure hardware RNG.Hardware wallets expose holders to massive losses
This produced seeds from a much smaller, partially predictable space. Attackers could recreate candidate seeds offline, match them to on-chain addresses, and steal funds without physical access. The risk is specific to wallets whose seeds were generated on affected Coldcard models and firmware, especially single-signature wallets created in that period. New seeds generated with fixed firmware or on other hardware/software are not subject to this particular flaw.
Security researchers emphasize that firmware updates fix future seed generation, but do not magically secure seeds already created with weak randomness; those addresses remain vulnerable unless funds are moved.
3. Market Impact And What To Watch
The exploit has distorted on-chain signals, as tens of thousands of BTC from older wallets were moved in a short window, which can resemble large-scale selling even when users are just migrating to safer setups.Coldcard exploit reaches 89 million
Analytics firms report a spike in small BTC deposits to exchanges and a surge in active addresses, reversing the usual move off exchanges pattern seen after events like FTX.Coldcard exploit has investors sending bitcoin back to exchanges
Separately, victims are reportedly exploring class-action lawsuits against Coinkite, which could set important precedents for hardware wallet liability.Class action threat over Coldcard bug
Watch for continued drains from known exploit-linked addresses, firmware advisories from Coinkite, and any legal or regulatory responses, since these will shape future wallet design and trust.
Conclusion
The Coldcard bug shows that even offline, do everything right self-custody can fail if randomness and seed generation are flawed. For Bitcoin holders, the key takeaway is that wallet security depends not just on keeping keys offline, but on how those keys were created and how quickly vulnerabilities are addressed. Future hardware wallet standards and legal outcomes from this incident could meaningfully change how crypto users balance self-custody, diversification, and institutional solutions.
