TLDR
A firmware flaw in Coldcard hardware wallets has enabled attackers to steal over 1,500 Bitcoin, with confirmed losses above $100 million and a possible total near $130 million.
- Galaxy Research estimates 1,596 BTC stolen across three confirmed attack waves, with a suspected fourth wave that could push losses to about 2,055 BTC.
- The exploit comes from a 2021 firmware bug that weakened seed phrase randomness on several Coldcard models, letting attackers reconstruct private keys without touching the devices.
- The incident is reshaping views on self-custody and hardware wallets as users migrate funds, while most stolen BTC remains traceable and currently unmoved on-chain.
Deep Dive
1. Scale Of The Theft
Investigators at Galaxy Research report that 1,596 BTC have been stolen from around 7,300 addresses across three confirmed waves of Coldcard-related attacks, with potential losses up to 2,055 BTC if a fourth wave is fully verified, worth nearly 130 million dollars at recent prices, according to their estimate.
Separate on-chain analysis has tallied roughly 1,816 BTC and 116 million dollars drained from more than 5,200 addresses over four waves, highlighting that multiple attacker groups are exploiting the same vulnerability in parallel, as described in a detailed incident report.
About 90 percent of the stolen Bitcoin (BTC) remains unmoved in attacker-controlled wallets, giving law enforcement and exchanges time to monitor and potentially block attempts to cash out.
The headline figure of over 1,500 BTC is already confirmed, and credible analyses suggest losses may still grow as more vulnerable wallets are discovered.
2. Firmware Bug Mechanics
Coinkites 2021 firmware change replaced the intended hardware random number generator for seed creation with a deterministic software generator, sharply reducing entropy on several Coldcard models and making some seeds guessable rather than effectively uncrackable, as explained in a technical custody analysis.
This flaw allowed attackers to compute private keys remotely from public information like serial numbers and timing data, without phishing or physical access, turning what should be air-gapped cold storage into a software break-in problem. New firmware patches stop the bug for future seeds, but any wallet created with vulnerable firmware remains exposed until funds are moved.
Even high-end hardware can fail if its randomness or seed generation logic is flawed, and that layer is almost impossible for ordinary users to independently verify.
3. Security And What To Watch
Coldcard and multiple security researchers have urged users to generate new seeds on fixed firmware and migrate funds carefully, while exchanges such as OKX report record inflows as holders temporarily prefer managed custody, according to recent commentary.
At the same time, analysts note that Bitcoins transparency makes large thefts harder to fully monetize, with all attacker-controlled coins tracked by investigators and compliance teams, a point stressed in an expert review. Phishing campaigns now impersonate hardware audits and Coldcard support to exploit user fear, which threat researchers have documented in a separate warning.
The immediate risk is to users with affected seeds and to those reacting rashly to fear or phishing; the broader lesson is to diversify custody setups, keep firmware current and treat hardware vendors as one component in a layered security strategy.
Confidence: high, based on multiple independent research reports and on-chain analyses.
Conclusion
The Coldcard exploit is one of the largest hardware wallet failures in Bitcoin history, driven not by the BTC protocol but by a subtle firmware bug in seed generation. It is forcing a rethink of self-custody assumptions, showing that cold storage still depends on correct code and trustworthy randomness, and that large-scale thefts remain visible and contested on-chain. For crypto users, the practical takeaway is to assume no single wallet or custodian is perfect and to build redundancy and verification into how they store significant amounts of Bitcoin.
