TLDR
A firmware vulnerability in Coldcard Bitcoin hardware wallets has enabled attackers to steal about 1,367 BTC, with observed losses now around $88.6 million and still evolving.
- Galaxy Research and others report three to four attack waves that have drained roughly 1,367 BTC, with current on chain estimates near $88.6 million.
- The root cause is a faulty random number generator in Coldcard firmware since 2021, which produced weak, guessable seed phrases on certain devices.
- The exploit is reshaping attitudes to self custody, driving coins back to exchanges and prompting renewed scrutiny of hardware wallet security.
Deep Dive
1. Scale Of The Losses
Galaxy Research and on chain analysts track at least 1,367 BTC stolen across roughly 4,585 Coldcard generated addresses, an estimated observed size of about $88.6 million in Bitcoin at recent prices. Reports from Galaxy and Decrypt describe three main attack waves, plus a likely fourth, with the latest wave alone draining about 207.7 BTC from more than 1,900 addresses and pushing totals to the current figure. Loss numbers are still approximate as new victim addresses are identified, but multiple sources converge on the $88.6 million range for confirmed losses so far.
Treat $88.6 million as a credible current tally, but expect the number to change as further vulnerable wallets are swept or rescued.
2. How The Coldcard Exploit Works
Investigations attribute the hack to a pseudo random number generator bug in Coldcard firmware introduced around March 2021, which caused some devices to use predictable software randomness instead of proper hardware entropy. That reduced effective entropy for seed phrases from the intended 128 bits to roughly 40 to 72 bits, making private keys computationally guessable for affected Mk3 and some Mk4, Mk5 and Q models, as detailed in technical writeups such as the PRNG analysis by Coinspeaker. Attackers appear to have precomputed candidate seeds using public data like serial numbers and clock values, likely assisted by large language models scanning open source firmware code, then swept funds in fast, highly automated batches. Bitcoins protocol itself was not hacked, as commentators like Anthony Pompliano have stressed; the failure sits entirely in one wallet products key generation.
This is a catastrophic product level entropy bug, not a Bitcoin network breach, highlighting how crucial high quality randomness is for any wallet.
3. Impact On Markets And Self Custody
The Coldcard incident has rattled confidence in self custody, with on chain data showing a spike in small Bitcoin deposits to exchanges and inflows of more than ten thousand BTC in the aftermath, as reported by CryptoQuant and others. Coverage from CoinDesk notes Bitcoin slipping below 63,000 dollars while narratives focus on hardware risk, not macro stress. Debate has intensified between those arguing that diversified custody and better audits can preserve self custody, and those pointing to ETFs and custodial solutions as safer for less technical holders. Regulators and competing wallet vendors are also being pushed to clarify how hardware wallets are classified and audited after what is now described as the largest hardware wallet hack in Bitcoin history.
Expect closer scrutiny of wallet firmware, more conservative guidance for non expert users, and a temporary tilt toward custodial or ETF style exposure until trust in hardware self custody is rebuilt.
Conclusion
Coldcards entropy bug has turned into an unprecedented hardware wallet exploit, with roughly $88.6 million in Bitcoin stolen by attackers who never touched victims devices. The episode underscores that Bitcoins security still depends heavily on the quality of the tools that generate and store keys, and it is likely to reshape both user behavior and industry standards around self custody and wallet audits in the months ahead.
