Need help? Support
BITCOIN
Tether Dominance USDT.D

Coldcard BTC theft losses reach $114M

Published 473 words 3 min read

TLDR

Losses from the Coldcard Bitcoin hardware wallet exploit are now estimated around $114 million, making it one of the largest self-custody failures in crypto history.

  1. Researchers have confirmed over $100 million in stolen BTC, with a fourth attack wave lifting on-chain estimates to roughly $114 million.
  2. The theft stems from a firmware bug that made Coldcard-generated seeds guessable, enabling attackers to reconstruct private keys without touching devices or tricking users.
  3. The incident is pushing some Bitcoin holders away from hardware self-custody toward exchanges and custodians, and highlights specific practices users should watch and improve.

Deep Dive

1. Scale Of Losses

Galaxy Research and others initially mapped three attack waves stealing about 1,367 BTC, roughly $88.6 million, from thousands of Coldcard-generated addresses.

Subsequent analysis identified a fourth coordinated sweep, bringing the estimated total to roughly 1,816 BTC, or about $114 million, across more than 5,200 addresses according to updated Coindesk and Decrypt coverage.

Galaxy still treats part of the fourth wave as pattern based rather than fully victim confirmed, which is why you will see slightly different loss numbers in reports.

Confidence: moderate because confirmed losses exceed $100M, while the full $114M figure depends on attack-pattern attribution that investigators are still validating.

2. Firmware Bug Root Cause

The exploit does not involve traditional hacking of devices or phishing users. Instead, a March 2021 firmware build error caused some Coldcard wallets to generate seeds using a weak software random number generator rather than the intended hardware entropy source.

That mistake reduced effective randomness far below the 128 bits expected for secure BIP-39 seed phrases, making it feasible for attackers to brute-force candidate seeds, derive addresses, match them against the blockchain, and sweep any BTC they found, as detailed in technical analyses.

Later Coldcard models improved entropy but still fell short, and importantly, updating firmware does not fix an already weak seed, so vulnerable wallets remain at risk until funds are moved to a new, properly generated seed.

3. Impact On Self-Custody And What To Watch

Onchain data shows a sharp spike in small Bitcoin transfers and increased flows from self-custody wallets toward exchanges and institutional custodians, reversing the post-FTX trend as noted by CryptoQuant and others and crypto.news.

Coinkite has shipped emergency firmware, halted shipments of affected devices, and urged users who generated seeds on flawed versions to rotate into new wallets, while researchers share attacker addresses with law enforcement and exchanges.

What this means

Self-custody still offers strong control, but this incident shows that entropy, firmware quality, multisig, and avoiding a single device or seed are critical levers for reducing catastrophic risk.

Conclusion

The Coldcard exploit illustrates that even highly regarded hardware wallets can fail if key generation is flawed, turning offline storage into a predictable target.

For crypto users, the takeaway is not that self-custody is dead, but that it must be practiced with diversity of wallets, robust randomness, and regular security reviews, especially after major disclosures like this one.

Educational information only. Crypto markets are volatile and this is not financial advice.


Top