TLDR
A long-running flaw in Coldcard Bitcoin hardware wallets has enabled attackers to brute-force weak seeds and drain large amounts of BTC, with losses now in the nine-figure range.
- A firmware error since 2021 weakened Coldcard seed randomness, making private keys guessable and enabling waves of theft totaling roughly $90 million to $120 million in Bitcoin.
- The incident is pushing many holders out of single-device self custody into exchanges and institutional custodians, creating a short term confidence shock for hardware wallets and Bitcoin storage practices.
- Affected users should rotate to new seeds and wallets quickly, and the market should watch further attack waves, legal fallout for Coinkite, and shifts in Bitcoin flows to exchanges.
Deep Dive
1. Scale And Root Cause
Coldcard maker Coinkite disclosed that a March 2021 firmware build error routed seed generation to a weak software pseudo?random number generator instead of the intended hardware source, cutting entropy dramatically. Analyses by Galaxy Research and others now track between about 1,367 BTC (around $88.6 million) and 1,816 BTC (around $118 million) stolen across several coordinated waves from thousands of addresses, with the exploit still active and more devices likely vulnerable. Reports stress that Bitcoin itself was not hacked; the failure is in the wallets seed generation, not the underlying protocol, as clarified by technical commentators in pieces such as the explanation that Bitcoin was not hacked linked from recent coverage.
Confidence: high, based on converging on chain data and multiple independent reports.
2. Self Custody Fallout
Because the exploit required no phishing, physical access, or obvious user mistakes, it has shaken faith in the idea that doing everything right with a single hardware wallet guarantees safety. Coverage of the crisis notes that smaller Bitcoin holders are now moving coins back to exchanges and regulated custodians, reversing the post?FTX trend where BTC flowed into self custody, and framing this as an anti self custody shift in the near term. Security experts, including Krakens CSO, are calling for independent testing of hardware wallets and stronger guarantees that production firmware truly uses robust randomness for key generation.
Self custody remains viable, but concentrating large holdings on one device and one vendor without independent checks now has a clearly documented failure mode.
3. What To Do And Watch
For Coldcard users, Coinkite and researchers emphasize that simply updating firmware does not protect wallets created with old weak seeds; the common recommended pattern is to treat any affected seed as compromised, generate a new one on a verified setup, and move funds promptly. Advisories urge using adequate fees so transactions confirm before attacker sweeps and following model specific migration instructions that Coldcard has published. At the ecosystem level, it is worth watching three things: continued attack waves and on chain tracing, emerging class action efforts against Coinkite, and whether net BTC flows continue shifting from self custody back toward exchanges and institutional custodians.
Conclusion
The Coldcard flaw is a hardware wallet entropy failure that has produced one of the largest confirmed Bitcoin losses tied to a single product, without touching the Bitcoin protocol itself. Near term, it undermines confidence in single device self custody and nudges some users toward regulated custodians, while longer term it is likely to accelerate demands for independent audits, diversified key setups, and more robust randomness in every wallet that touches Bitcoin.
