TLDR
A critical firmware flaw in Coldcard Bitcoin hardware wallets has enabled attackers to drain well over $100 million worth of BTC from vulnerable wallets.
- Galaxy Research and others estimate roughly 1,6002,000 BTC stolen across multiple attack waves, with total losses now in the $100130 million range.
- The exploit comes from a seed-generation bug that weakened randomness on certain Coldcard models and firmware, making wallet seeds guessable without physical access.
- The incident is reshaping the self-custody debate but does not affect Bitcoins protocol; stolen coins are highly traceable, and Coldcard has urged users to migrate funds.
Deep Dive
1. Scale Of The Exploit
Analysts at Galaxy Research and other firms report that more than $100 million in Bitcoin has been stolen through the ongoing Coldcard wallet exploit, with estimates ranging from about 1,600 BTC to roughly 2,055 BTC tied to three confirmed and a suspected fourth wave of attacks, as detailed in coverage of the Coldcard exploit topping $100M.
Independent reporting suggests the theft has escalated to around $116 million, or 1,816 BTC, across over 5,200 addresses and four waves, with the most recent sweep alone moving hundreds of BTC, according to the Coldcard hack fourth-wave analysis.
Most of the stolen BTC remains in attacker-controlled wallets and has not yet been moved through exchanges or mixing services.
2. Firmware Flaw And Impacted Users
The root cause is a flaw in Coldcards seed-generation process introduced in a 2021 firmware change. Affected devices fell back to a weaker software random-number generator instead of using the intended hardware entropy source, shrinking effective randomness from typical 128-bit levels down to roughly 4072 bits on some models, as explained in a technical breakdown of the Coldcard firmware entropy bug.
Because seed phrases are the master secret for all wallet keys, this weaker entropy made it computationally feasible for attackers to brute-force seeds and reconstruct private keys remotely. Reports indicate Mk3, Mk4, Mk5 and Q devices set up on specific vulnerable firmware versions are at risk, while wallets created using Coldcards dice-roll option are considered safe because they never relied on the flawed code.
Coldcards manufacturer, Coinkite, has released fixed firmware, but updating alone does not protect seeds that were already generated under the bug; users must create new seeds and move funds to truly secure wallets.
3. Self-Custody, Traceability, And What To Watch
Coldcards developers have issued an urgent warning for users to migrate funds, noting that the active exploit has drained up to about $114 million from self-custodied wallets and remains ongoing, according to the Coldcard advisory to move Bitcoin.
The episode highlights a key trade-off of self-custody: it removes exchange counterparty risk but adds software, hardware, and operational risks around seed generation and backups. At the same time, it showcases Bitcoins transparency, as investigators and exchanges can monitor attacker addresses in real time and potentially block cash-outs, a point emphasized in analysis of the Coldcard exploit and spending challenges.
If you use Coldcard or any hardware wallet, the critical questions are firmware quality, seed-generation method, and how quickly you respond to credible security advisories.
Conclusion
The Coldcard exploit is a major hardware wallet failure, not a failure of Bitcoin itself, and it has turned a subtle entropy bug into more than $100 million in real losses.
For crypto users, the incident underlines that self-custody is only as safe as the underlying firmware and seed practices, while also showing that stolen BTC remains visible and constrained by on-chain traceability. Watching follow-up audits, firmware responses, and how much of the attackers haul can actually be laundered will be key for understanding both security and regulatory implications from here.
