TLDR
A critical flaw in Coldcard Bitcoin hardware wallets has let attackers drain nearly $114 million from users, turning a self-custody tool into one of cryptos worst wallet failures.
- On-chain analysis points to about 1,816 BTC, roughly $114 million, swept from Coldcard-generated addresses across several attack waves.
- The losses come from a five-year seed-generation bug that produced weak private keys, while the Bitcoin protocol itself remains uncompromised.
- The incident is pushing coins back to exchanges and driving calls for independent hardware wallet testing and more diversified custody setups.
Deep Dive
1. Scale Of The Losses
Galaxy Research and other analysts have tracked multiple coordinated theft waves targeting Coldcard-generated addresses, estimating around 1,816 BTC, or about $114 million, stolen so far, based partly on transaction patterns rather than victim confirmations. Recent coverage describes three confirmed waves totaling 1,367.05 BTC, about $88.6 million, with a fourth suspected wave raising the figure toward $114 million across more than 5,000 addresses, making it arguably the largest hardware wallet incident in Bitcoin history. You can see these estimates in reports from Galaxy and Decrypt and Coinspeakers technical summary.
Confidence: high, but totals for the latest attack wave rely partly on on-chain heuristics rather than direct victim reporting.
2. What Went Wrong Technically
Coldcards firmware contained a pseudo random number generator vulnerability that quietly weakened wallet seed phrases from March 2021 onward, reducing entropy far below the intended 128 bits for secure BIP-39 seeds. A misconfigured build caused affected devices to fall back to a software PRNG with roughly 40 to 72 bits of effective randomness, making it feasible for attackers to brute-force private keys and sweep funds, as detailed in this PRNG flaw analysis. Crucially, the Bitcoin network itself was not hacked, a point stressed in Bitcoins protocol clarification, which separates third-party wallet failures from core protocol security.
3. Market And User Response
The incident has triggered a sharp behavioral shift: small Bitcoin holders moved about 39,600 BTC in sub-1 BTC transactions and sent 7,300 BTC to exchanges in a single day, levels last seen after the FTX collapse, suggesting a search for perceived safety in custodial venues, according to CryptoQuant data cited by Decrypt. Regulators, analysts, and security leaders are calling this a wake-up call for hardware wallet makers, urging independent lab validation of entropy sources and more rigorous firmware audits. At the user level, experts now emphasize multi-vendor setups, true high-entropy seed creation, and avoiding reuse of any seed ever generated on vulnerable Coldcard firmware.
Self-custody is only as strong as your key generation and vendor diversification, so treating hardware wallets as infallible and relying on a single device or seed greatly increases tail risk.
Conclusion
The Coldcard incident shows that even respected hardware wallets can fail in subtle ways that only surface once real money is drained. The Bitcoin protocol remains intact, but the trust model around self-custody has been shaken, driving coins back to exchanges and spotlighting hidden assumptions about wallet security. Going forward, the most resilient setups will likely combine independent entropy, multiple vendors, and ongoing scrutiny of firmware rather than blind faith in any single device.
