TLDR
A critical firmware bug in Coldcard hardware wallets has allowed attackers to steal more than 1,300 BTC, with estimated losses now near $88 million.
- A seed generation flaw dating back to 2021 made some Coldcard keys guessable, enabling coordinated sweeps draining roughly 1,100 to 1,367 BTC from thousands of addresses.
- Risk is concentrated in seeds created on specific Mk3, Mk4, Mk5 and Q firmware without extra entropy or passphrases, exposing limits of single-device self custody.
- Victims are organizing legal action and regulators may scrutinize hardware wallet standards, while on chain data shows many smaller holders moving BTC back to exchanges for perceived safety.
Deep Dive
1. Scale Of Losses
Initial reports described about 594 BTC stolen in 25 minutes from roughly 500 Coldcard wallets. Subsequent on chain analysis expanded this to 1,082.65 BTC across 1,196 addresses in a 41-minute window, and then to a total of 1,367.05 BTC drained across three waves and 4,585 addresses.
A separate legal-focused report notes losses exceeding 1,300 BTC as victims prepare collective action against Coinkite, Coldcards maker, over the wallet bug and resulting thefts of more than $88 million in BTC in just a few days.
Confidence: high because multiple independent technical and legal analyses converge on the same attack pattern and magnitude, even though precise totals may still shift slightly as more addresses are traced.
2. Technical Cause And Who Is At Risk
The core problem was a firmware build error that bypassed Coldcards hardware random number generator and fell back to a predictable MicroPython software RNG for seed creation, as explained in a detailed Coldcard exploit analysis. For affected Mk3 devices, effective seed entropy dropped to around 40 bits instead of 128; some Mk4, Mk5 and Q devices had about 72 bits, still weak enough for brute force.
Risk is highest for users who generated seeds on specific firmware versions from March 2021 onward, without adding independent entropy (such as extensive dice rolls) or using a strong BIP-39 passphrase, and who held funds in single-signature wallets. Multisig setups and seeds with extra entropy or passphrases appear largely outside the observed attack pattern.
Coinkite has released fixed firmware and urges users with possibly vulnerable seeds to treat them as compromised and migrate funds to new wallets generated under corrected randomness.
Even with reputable hardware wallets, you should assume firmware bugs are possible and layer defenses like extra entropy, strong passphrases and multisig for significant BTC holdings.
3. Legal And Market Fallout
Coinkite now faces a class action threat as victims coordinate globally, though legal experts are split on whether hardware wallet makers are liable for user losses and how product defect and negligence standards apply in crypto.
At the same time, on chain data shows exchange inflows spiking after the exploit, particularly from smaller holders sending BTC to centralized venues they perceive as safer than a single compromised hardware brand. This reverses the self-custody trend seen after events like the FTX collapse and may trigger broader discussion about defense in depth for custody.
Conclusion
A long-lived randomness bug in Coldcards firmware turned unguessable seeds into guessable ones, enabling automated sweeps of more than 1,300 BTC and exposing a critical weakness in single-device self custody. The incident is likely to reshape how Bitcoin users think about hardware wallets, push manufacturers toward stricter entropy and audit standards, and prompt some holders to diversify custody methods rather than relying on any single wallet, exchange or firmware line.
