TLDR
A long-standing Coldcard hardware wallet bug is being actively exploited again, draining Bitcoin from thousands of addresses and shaking confidence in self-custody.
- A flawed Coldcard firmware update from 2021 left some seeds guessable, and multiple exploit waves since late July have drained over 1,500 BTC, with losses possibly nearing $130 million.
- The breach is prompting defensive moves, from long-dormant wallets waking up to coins shifting back to exchanges, while Bitcoins price reaction has remained relatively modest.
- For BTC users, the key lesson is to avoid trusting a single device or seed, strengthen firmware and key generation practices, and follow ongoing Coldcard guidance and on-chain investigations closely.
Deep Dive
1. Exploit Scale And Root Cause
Investigators link the thefts to a firmware bug in Coldcard devices that changed how wallet seeds were generated in March 2021. Instead of using the hardware random number generator, affected versions relied on a deterministic fallback, shrinking the possible seed space and making some keys guessable offline, as detailed in independent reviews from CryptoSlate and others.
Galaxy Research now estimates around 1,596 BTC stolen from roughly 7,300 addresses across three confirmed waves, with total losses potentially reaching 2,055 BTC, close to $130 million, if a suspected fourth wave is fully verified. This is echoed by reports that the Coldcard hack has escalated to about 1,816 BTC and $116 million.
Coinkite, Coldcards manufacturer, has acknowledged the flaw, shipped patched firmware, halted shipments of affected units, and urged users whose seeds were created on vulnerable firmware to move funds to newly generated wallets.
The incident is not a Bitcoin protocol failure, but a device-specific randomness bug that turns air-gapped storage into a target if the original seed was weak.
2. Impact On BTC Users And Markets
The exploit is driving visible behavioral shifts. One analysis found transfers of less than 1 BTC surged to 39,600 BTC in a single day as small holders moved coins after learning Coldcard keys had been guessable for years, according to Decrypts Coldcard security write-up.
Reports also describe dormant wallets from as far back as 2013 suddenly moving hundreds of BTC as Coldcard fear deepens, and on-chain data shows sub-1 BTC amounts flowing back to exchanges at levels not seen since the FTX collapse. At the same time, market coverage notes that BTC and ETH have only slipped slightly, with price down around 1 percent in the incident window, suggesting reputational damage is larger than immediate price damage.
The shock is mostly about trust in tooling and operational security rather than a broad macro selloff, but it is changing where and how users park their BTC.
3. Security Lessons And What To Watch
Security researchers emphasize that any wallet that both generates and stores a single seed is a potential single point of failure. Articles on the incident stress that initial seed entropy, firmware quality, and diversification matter more than air-gapped marketing alone, especially when a deterministic random generator can be abused.
Coldcard and independent researchers have highlighted several mitigations in principle: moving away from vulnerable seeds, favoring setups with stronger randomness sources or additional factors such as robust passphrases or multisig, and treating firmware updates and independent audits as ongoing necessities rather than one-time checks. Galaxy warns that more actors may still exploit exposed seeds while affected devices remain in use, and that most stolen BTC has not yet moved, which keeps the story live.
For BTC users, the practical edge is to treat wallet choice and key generation as an evolving security problem, monitor vendor advisories, and avoid assuming any single device or setup is infallible.
Conclusion
The renewed Coldcard exploit wave shows that self-custody risk can originate years earlier at the moment a seed is generated, even on respected hardware wallets.
Losses in the tens of thousands of BTC, combined with visible shifts in on-chain behavior, are pushing Bitcoin users to reassess their reliance on single devices, firmware assumptions, and air-gapped marketing claims.
Going forward, the real differentiation will come from how quickly wallet makers, auditors, and users adapt their security models to reduce single points of failure while keeping self-custody viable for ordinary BTC holders.
