TLDR
Losses from the Coldcard hardware wallet exploit have climbed to roughly $116 million in stolen Bitcoin, and vulnerable wallets are still being drained.
- The exploit has swept about 1,816 BTC (around $116 million) from more than 5,200 addresses across four attack waves.
- A firmware bug from 2021 weakened seed randomness on certain Coldcard devices, exposing single?key wallets, though the Bitcoin protocol itself remains intact.
- Estimates suggest losses could approach $130 million as more wallets are hit, while firmware patches, migration tools and investigations shape the path to containment and any recovery.
Deep Dive
1. Scope Of Losses
Analysis by Galaxy Research and others indicates the Coldcard exploit has stolen roughly 1,816 BTC, or about $116 million, across four waves of attacks from more than 5,200 addresses, with sweep rates far above normal background activity as attackers drain exposed wallets in clusters of transactions. Reports also note that a suspected fourth wave pushed cumulative losses from an initial $30 million to $75 million, then $89 million and finally about $116 million as more compromised seeds were discovered and exploited, with most of the stolen BTC still sitting unmoved in attacker-controlled addresses.
Other security researchers and media put the upper bound somewhat higher, estimating total losses could reach around 2,055 BTC, nearly $130 million, once all confirmed and suspected incidents tied to the same flaw are accounted for, underscoring that the figure in your headline is a midpoint, not a final tally.
The loss number is still evolving, and any Coldcard user in the affected cohort should assume risk is active until they have definitively migrated to a safe setup.
2. Cause And Whos At Risk
The root cause is a Coldcard firmware change introduced in 2021 that routed seed generation through a weaker software pseudo?random generator instead of the hardware true random source, drastically reducing entropy (randomness) in the 24?word seed phrases that control wallet funds. On some models this cut effective entropy from a standard 128?bit level to roughly 4072 bits, turning what should be practically unguessable keys into a search space attackers can brute?force with enough computing power.
Reports highlight that certain Mk3 devices on firmware 4.0.1 or later, and Mk4, Mk5 and Q devices on older firmware, are affected, particularly when funds sit in simple single?signature wallets. Wallets whose seeds were generated via the manual dice?roll method with sufficient rolls, or protected by strong additional BIP?39 passphrases, appear largely safe, and the bug sits in Coldcards firmware, not in the Bitcoin network itself.
Self?custody security hinges on how keys are created, not just on keeping devices offline, so relying on a single vendors default key?generation path can create hidden systemic risk.
3. What Happens Next
Coldcards maker Coinkite has pushed emergency firmware updates and publicly urged users to treat this as urgent, generate new seeds on fixed firmware and carefully migrate funds, while miners like MARA have opened tools such as Slipstream to help victims move coins without exposing transactions to public mempools where attackers can intercept them. At the same time, investigators have shared attacker and victim address sets with law?enforcement and exchanges, and industry figures are debating options such as victim funds that buy claims on stolen coins.
Recovery prospects are uncertain: some analysts see only a partial chance of reclaiming funds through seizures or negotiated returns, while others focus on preventing further losses as new attackers copy the exploit. The broader impact is a renewed push for diversified key?generation practices, better audits of wallet firmware and more layered setups such as multisig that reduce dependence on one device.
Risk note: Further waves of draining remain possible while vulnerable seeds exist, and rushed migrations can expose users to scams or front?run attacks if transactions are not handled carefully.
Conclusion
The Coldcard incident is a major failure of hardware wallet key generation, not a breach of Bitcoin itself, and it has already cost users well over $100 million. For crypto holders, the key takeaway is that not your keys, not your coins only holds if those keys are generated with robust, audited randomness and protected by layered setups, rather than trusting a single devices defaults. How fast affected users migrate, how well investigators track attacker wallets and how the industry hardens key?generation practices will determine whether this remains a contained hardware crisis or reshapes trust in self?custody more broadly.
