TLDR
A critical flaw in Coldcard Bitcoin hardware wallets has enabled one of the biggest self-custody breaches, with losses already over $100M and possibly approaching $130M in BTC.
- Galaxy Research and others have traced at least 1,596 BTC stolen so far, with a potential upper bound near 2,055 BTC (about $130M) as more waves are analyzed.
- The root cause is a firmware bug that made some Coldcard-generated seed phrases partially predictable, letting attackers reconstruct private keys without phishing or physical access.
- The incident is shaking confidence in hardware wallets, spurring calls for deeper audits and arguably strengthening the appeal of institutional-grade custody such as spot Bitcoin ETFs.
Deep Dive
1. Scale Of The Exploit
Analysts at Galaxy Research report at least 1,596 BTC stolen from roughly 7,300 addresses across three confirmed attack waves, plus smaller related incidents, with a suspected fourth wave that could bring losses to about 2,055 BTC, or nearly $130M at current prices.Galaxy estimate
Other tracking suggests around 1,816 BTC (about $116M) have already been drained across four waves, highlighting that confirmed losses are comfortably above $100M even if the full 2,055 BTC figure is not yet verified.Wave breakdown
Coldcards manufacturer Coinkite and multiple media outlets stress that the attack is ongoing, with more vulnerable wallets likely to be discovered as the flaw becomes widely understood.Coldcard warning
Confidence: high because independent research teams and several outlets converge on similar loss ranges and timelines.
2. Firmware Bug And Risk
The exploit stems from a firmware change in 2021 where Coldcard devices used a software pseudo-random number generator instead of the intended hardware randomness for seed creation, dramatically shrinking the effective key space on certain models.Technical explanation
That mistake made some seed phrases guessable from device details and timing, allowing attackers to derive private keys and sweep funds from air-gapped wallets without malware, phishing, or physical access.Bug origin
Importantly, the Bitcoin network itself was not compromised; only wallets whose seeds were generated with the flawed firmware are at risk, and updating firmware alone does not fix already-weak seeds.Risk scope
Hardware wallets reduce online risk, but their security still depends on correct firmware and strong randomness, not just being offline.
3. Self-Custody, Wallets, And Whats Next
Coinkite has urged Coldcard users to treat the issue as urgent, upgrade devices, generate new seeds, and carefully migrate funds, while emphasizing that importing old vulnerable phrases into another wallet does not remove the underlying risk.User advisory
The breach is intensifying debate over self-custody: critics argue users have simply swapped counterparty risk for software and operational risk, while proponents call for better audits, diversified setups, and stronger entropy practices.Custody debate
Some analysts suggest the event could bolster the case for spot Bitcoin ETFs and other institutional-grade custodial solutions, where large financial institutions maintain hardened custody stacks as a feature rather than a bug.ETF angle
Expect more scrutiny of wallet vendors, more demand for independent security reviews, and a renewed split between DIY self-custody and regulated custodial services.
Conclusion
The Coldcard exploit shows that even respected hardware wallets can harbor subtle firmware flaws that convert cold storage into a systemic single point of failure. Bitcoin itself remains intact, but trust in self-custody tooling is dented.
For crypto users, the key shift is that wallet randomness, audits, and diversification now matter as much as the not your keys, not your coins slogan, and custody choices will likely be reassessed in light of this breach.
