TLDR
An exploit in Coldcard Bitcoin hardware wallets has drained roughly $8889 million in BTC by abusing a firmware bug in seed generation, and coordinated attacks are still ongoing.
- Galaxy Research and others now track about 1,367 BTC, around $88.6 million, stolen from roughly 4,585 Coldcard-generated addresses across multiple waves of attacks.
- The root cause is a 2021 firmware error that made some seed phrases predictable, hitting long-term self-custody users and briefly pressuring Bitcoins price and on-chain indicators.
- Coldcard has patched firmware and destroyed vulnerable inventory, but seeds created on affected devices remain unsafe, with legal, security and self-custody debates likely to intensify.
Deep Dive
1. Scale And Exploit Mechanics
Researchers at Galaxy estimate three confirmed attack waves draining about 1,367 BTC, or roughly $88.6 million, from 4,585 addresses linked to Coldcard wallets, with a fourth wave being analysed as well. Reports describe an ongoing exploit that systematically sweeps vulnerable wallets, often grouping victims in coordinated transactions and using scripted patterns that look programmatic rather than manual.
The underlying flaw traces to a March 2021 Coldcard firmware build that routed seed generation to a predictable software randomizer instead of the hardware random number generator, shrinking the true randomness of recovery phrases and making private keys reconstructable offline by attackers. Media coverage notes that updating firmware protects new seeds but cannot retroactively secure old ones created while the bug was live, so those addresses remain at risk even if devices are now patched.
2. Impact On Users And The Bitcoin Market
Most affected wallets belonged to long-term holders, with average coin dormancy over three years, meaning the exploit hit people who deliberately chose cold storage for safety. One victim reportedly lost over 18 BTC in minutes despite keeping his device offline and locked away, underscoring that the weakness was in key generation rather than physical or network access.
On-chain, the incident triggered unusually large migrations of BTC from self-custody back to exchanges, with small transfers under one BTC spiking to levels last seen around the FTX collapse and net exchange inflows rising. Headlines also tie the hack to Bitcoin slipping below about $63,000 as security fears added short-term selling pressure, even though analysis from industry figures stresses that Bitcoins protocol itself was not hacked.
Security failures in popular hardware wallets can move both coins and sentiment, so market signals around inflows, outflows and price may reflect fear-driven repositioning more than fundamental shifts.
3. Ongoing Risk, Responses And What To Watch
Coldcards maker, Coinkite, has acknowledged the bug, halted shipments of affected units, destroyed remaining vulnerable inventory in its facilities and shipped updated firmware, while researchers have flagged hundreds of suspected attacker addresses to law enforcement and compliance teams. Victims are reportedly exploring class-action litigation, and legal analysis suggests these cases could set important precedents for hardware wallet liability.
Practically, the risk is now concentrated in Coldcard seeds generated on specific firmware versions after March 2021. Because the attacker is iterating through a finite set of weak keys, observers warn that every single-signature wallet created under those conditions may eventually be swept unless funds are migrated to seeds generated with proper entropy or to alternative custody setups.
Conclusion
The Coldcard exploit shows that self-custody is only as strong as the software and randomness behind your keys. A single firmware bug in a trusted hardware wallet has translated into one of the largest wallet-side Bitcoin thefts on record, distorted on-chain metrics and shaken confidence, even while Bitcoins core protocol remains secure. For crypto users, the key takeaway is to treat wallet security and seed generation quality as critical infrastructure and to closely monitor both vendor disclosures and unusual movements in custody patterns when evaluating risk.
