Need help? Support
BITCOIN
Tether Dominance USDT.D

Coldcard exploit losses climb as attacks continue

Published 670 words 4 min read

TLDR

A long running firmware bug in Coldcard Bitcoin hardware wallets is being actively exploited, with multiple attack waves pushing losses toward the nine figure range in USD terms.

  1. Researchers have confirmed at least 1,367 BTC stolen (around $89 million), while on chain estimates now approach 1,816 BTC (about $114 million) across four attack waves.
  2. The root cause is a 2021 random number generator bug that produced guessable seed phrases on some Coldcard devices, affecting single signature wallets but not Bitcoin itself or multisig setups.
  3. Coldcard has shipped emergency firmware and halted shipments as analysts warn every vulnerable wallet may eventually be drained, driving calls for independent audits and more cautious self custody practices.

Deep Dive

1. Scale And Current Status

Galaxy Research and other analysts have traced at least 1,367 BTC, roughly $88 to $89 million, drained from around 4,585 Coldcard generated addresses in three confirmed waves of theft, making it the largest known hardware wallet exploit in Bitcoin history. Articles from CoinDesk and others now report a likely fourth wave of sweeps, with total impacted Bitcoin near 1,816 BTC, or about $114 million, across more than 5,200 addresses, based on elevated sweep patterns and replace by fee usage in recent blocks, though some of these totals remain estimates rather than fully confirmed losses.

The latest transactions follow a distinctive pattern of rapid, batched drains from vulnerable addresses into newly created destination wallets, and investigators caution that any Coldcard seed created with affected firmware is at risk until funds are moved to a securely generated wallet.

Confidence: high, because multiple independent on chain teams and the manufacturer have published consistent figures and technical details.

2. Cause, Scope, And What Was Not Hacked

The exploit stems from a firmware build error introduced around March 2021 that silently switched seed generation from Coldcards hardware true random number generator to a weaker pseudo random generator with far fewer bits of entropy, as detailed in a technical write up on the Coldcard PRNG vulnerability.

With entropy cut from an intended 128 bits down to roughly 40 to 72 bits depending on the model, attackers could feasibly brute force recovery phrases offline and reconstruct private keys, then sweep coins from wallets that had never been connected to the internet. Crucially, Bitcoins protocol was not breached; commentators such as Anthony Pompliano have stressed that this is a third party hardware wallet failure, not a Bitcoin network hack.

So far, evidence indicates single key Coldcard seeds generated under the flawed firmware are vulnerable, while multisignature setups and seeds created with strong manual randomness (for example, sufficient private dice rolls) are far better protected.

3. Security Lessons And What To Watch

Coldcards maker Coinkite has released emergency firmware for all affected models, halted new shipments, and reportedly destroyed remaining vulnerable units, but updates cannot retroactively secure seeds that were already generated with weak randomness. Analysts at Kraken and Galaxy are using this incident to push for independent firmware and entropy audits so that wallet makers are not the sole judges of their own key generation quality.

On chain data shows many users reacting by moving Bitcoin from self custody back to exchanges and institutional custodians, reversing the post FTX trend as described in analysis of the Coldcard exploits impact on flows. A fourth wave using replace by fee transactions suggests some victims may have narrow windows to rescue funds, but researchers warn that, over time, every vulnerable wallet is likely to be swept.

What this means

Hardware wallets still reduce many risks, but their safety depends on high quality, independently verified randomness and avoiding single points of failure; diversifying custody methods and monitoring vendor security notices becomes critical.

Conclusion

The Coldcard exploit shows that even air gapped hardware wallets can fail when firmware silently weakens seed randomness, turning long trusted cold storage into a target for large scale automated theft.

For crypto users, the key distinction is between Bitcoins protocol, which remains intact, and the third party tools that generate and hold keys. The ongoing attack waves and shifting custody flows highlight that self custody delivers control only when the underlying hardware, software, and operational practices are robust, audited, and periodically refreshed.

Educational information only. Crypto markets are volatile and this is not financial advice.


Top