TLDR
Coldcard hardware wallets suffered a major exploit via a firmware bug, and the company has halted shipments after hackers drained roughly $8688 million in Bitcoin.
- A seed generation vulnerability in Coldcard firmware has enabled attackers to drain about 1,367 BTC from thousands of wallets, with multiple waves of theft still ongoing.
- Bitcoin itself was not hacked, but trust in self-custody hardware has been shaken because the flaw required no phishing, no physical access, and no obvious user error.
- Coldcard has stopped shipping affected devices, destroyed remaining vulnerable units, and is urging users to migrate funds, while victims explore legal action and on-chain recovery looks limited.
Deep Dive
1. Scale Of The Exploit And Shipment Halt
Researchers at Galaxy and others now estimate around 1,367 BTC, worth roughly $8688 million, has been drained from Coldcard-generated addresses across at least three confirmed attack waves, with a likely fourth underway. Reports describe more than 4,500 affected addresses and sweep rates many times normal, indicating a coordinated operation rather than opportunistic theft.
Coverage from Benzinga notes that Coldcard confirmed the vulnerability, halted shipments, and destroyed all remaining units with the affected firmware in its facilities, focusing on contacting customers with migration steps and helping them move funds safely from vulnerable wallets. CryptoPotato similarly reports that Coinkite, Coldcards maker, has destroyed exposed inventory and paused shipments while working with law enforcement and the hardware wallet community.
This is one of the largest hardware wallet failures seen in Bitcoin and has triggered emergency operational changes at the vendor, not just a minor patch.
2. Bitcoin Versus Wallet Risk
Technical analyses explain that the bug is in Coldcards seed generation, specifically a pseudo-random number generator mistake that produced far less entropy than the 128 bits expected for BIP 39 seed phrases, making some recovery phrases realistically brute forcible. Coinspeaker details how a misconfigured macro caused Coldcard to fall back to a weak software PRNG, reducing effective randomness for seeds created since March 2021.
Anthony Pompliano and others have stressed that Bitcoin itself was not hacked and that there is no known protocol-level vulnerability, framing this as a third-party custody failure rather than a break of the network or consensus rules. The incident highlights that self-custody depends not only on user behavior but also on the integrity of hardware and firmware choices made by small vendors.
3. User Actions, Legal Fallout, And Recovery Odds
Coldcard is telling users to create new seeds on patched or unaffected devices and migrate funds, noting that merely updating firmware cannot secure old, weak seeds. Galaxy researchers warn that every vulnerable single-signature Coldcard wallet is likely to be drained if funds are not moved, and some transactions in the mempool show fee races where victims try to outbid attackers.
Bitcoin.com reports victims preparing class actions against Coinkite, while other commentators suggest recovery odds are low given the on-chain nature of the theft and the lack of centralized liability funds. The episode is likely to influence how regulators, courts, and users think about hardware wallet responsibilities and disclosures.
Risk note: If you self-custody BTC on any hardware wallet, this event underlines the need to understand how seeds are generated and to monitor vendor security notices closely.
Conclusion
The Coldcard exploit is a high-impact hardware wallet failure that has forced the company to halt shipments and triggered large, ongoing Bitcoin losses. It does not compromise Bitcoins protocol, but it shows how a subtle randomness bug can devastate even careful self-custody users. Over the next weeks, the key signals will be how fast vulnerable users migrate, whether courts and regulators define new responsibilities for wallet makers, and whether confidence in self-custody hardware stabilizes or shifts toward alternative custody models.
