Coldcard Hardware Wallet Flaw Sparks $89 Million Bitcoin Heist Across 4,500 Addresses

A catastrophic vulnerability in Coldcard hardware wallets has enabled attackers to drain approximately 1,367 BTC ($89 million) from 4,585 addresses across three attack waves. The flaw, introduced in March 2021 firmware, weakened seed generation randomness to just 40 bits on some models, allowing private keys to be brute-forced offline. The attack remains ongoing, with researchers urging immediate fund migration.

Coldcard Hardware Wallet Flaw Sparks $89 Million Bitcoin Heist Across 4,500 Addresses

Image related to Coldcard Hardware Wallet Flaw Sparks $89 Million Bitcoin Heist Across 4,500 Addresses. (Photo: Metro Daily Reporter)

Table of Contents

A Crisis of Trust in Hardware Wallets

Bitcoin's self-custody ethos is facing its most severe test in years as a fundamental flaw in Coldcard hardware wallets has resulted in the theft of nearly $89 million from thousands of users . What was initially reported as a $38 million heist from approximately 500 wallets has now ballooned across three distinct attack waves, exposing a vulnerability that undermines the very promise of hardware wallets: that funds remain safe even if the device never touches the internet .

The attacker never needed physical access to a single device. By exploiting a firmware error that weakened the randomness of seed generation, they were able to reconstruct private keys offline and systematically drain wallets that had been created over the past five years . The breach has triggered a wave of panic, with small Bitcoin transfers surging to levels not seen since the FTX collapse, and has reignited a fierce debate about the safety of self-custody versus centralized custody solutions .

The Technical Failure: From 128 Bits to a Solvable Puzzle

The root cause of the catastrophe traces to a single configuration error introduced in Coldcard firmware version 4.0.0, shipped in March 2021 . The firmware was designed to use the device's hardware random number generator (RNG) to create seed phrases, which should provide 128 bits of entropy—a number so astronomically large that brute-forcing it is computationally impossible.

However, a production configuration error caused the firmware to silently fall back to a software-based pseudo-random number generator instead . The software generator was seeded from non-secret data like the chip's unique ID and timer registers, collecting no fresh entropy after initialization . This meant that the "random" seeds generated by affected devices were, in fact, deterministic and predictable.

The impact varied by device model. Coinkite estimates that on Mk2 and Mk3 devices running affected firmware, the effective entropy collapsed to roughly 40 bits—a number that modern cloud computing can brute-force . On newer Mk4, Mk5, and Q devices, the entropy was around 72 bits—still significantly below the intended 128-bit standard, though not yet exploited in the current attack .

The Three Waves: How the Attack Evolved

Galaxy Research has tracked three distinct attack waves, each with different operational characteristics suggesting either a single operator adapting their methods or multiple attackers exploiting the same vulnerability .

Wave One (July 30, 1:10–1:51 UTC): The initial attack drained approximately 1,083 BTC (worth about $70 million at the time) from 1,196 addresses in just 41 minutes . The attacker processed exactly one victim per transaction, routing funds to a handful of shared collector addresses. Chainalysis found the attacker targeted the largest balances first, pulling more than $30 million in the opening ten minutes .

Wave Two: A second wave followed a similar pattern to the first, scaling the operation and adding to the haul .


Wave Three (flagged August 1): The third wave departed significantly from the earlier pattern. It drained 207.7 BTC from 1,912 addresses—averaging just over a tenth of a Bitcoin per victim—confirming that the attacker has moved to smaller balances as the more profitable end of the vulnerable key space has been picked over . Unlike the first two waves, this one sent each victim's coins to its own unique destination rather than shared collector addresses, used a different transaction format, and batched an average of six victims per sweep .

Galaxy believes each wave is internally consistent with a single operator but will not link the three waves to each other. The cumulative total now stands at 1,367.05 BTC, worth approximately $88.6 million, across 4,585 addresses . Galaxy has reported roughly 600 suspected attacker-controlled addresses to federal investigators and compliance firms .

Which Devices and Firmware Are Affected

Coinkite has significantly expanded its advisory since the initial disclosure. The vulnerability exposure depends on the firmware version running when the seed was created, not the version currently installed .

Mk2 and Mk3: Seeds generated on Mk3 firmware versions 4.0.1 through 4.1.9 are affected (Coinkite's initial advisory did not name Mk2, but Block researchers place both Mk2 and Mk3 versions 4.0.0 through 4.1.9 on the vulnerable path) .

Mk4 and Mk5: Seeds created before standard firmware version 5.6.0 are affected, as well as Edge builds before 6.6.0X .

Coldcard Q: Seeds created before standard version 1.5.0Q or Edge version 6.6.0QX are affected .

Fixed firmware has been released for each affected model. However, as Coinkite has made clear, updating the firmware does not repair an existing seed. A seed created with weak entropy remains weak forever. Users must generate an entirely new wallet on updated hardware and move their coins .

There is one exception: seeds generated with at least 50 independent, fair, private dice rolls during setup are not considered at risk, as this external entropy cannot be undone by the firmware bug . Strong BIP-39 passphrases also add a significant layer of protection, though Coinkite still recommends migration .


The Human Impact: When Doing Everything Right Isn't Enough

Perhaps the most unsettling aspect of this incident is that victims did everything security best practices dictate. Canadian coach Jonathan Goodman shared on X that 18.25 BTC (approximately $1.6 million Canadian) was swept from his wallets in a seven-minute span on July 29, despite his keys sitting in a physical safety deposit box that never touched the internet .

"Perhaps the hardest part about this is that I did everything right," Goodman wrote. He is now filing reports with police and the Ontario Securities Commission .

Galaxy's Alex Thorn noted that the stolen coins had sat untouched for years—an average dormancy of 3.18 years—underscoring that the victims were long-term holders who had followed the principle of "not your keys, not your coins" and had placed their trust in a reputable hardware wallet .

Market Reaction and Broader Implications

The incident has sent shockwaves through the crypto market. Bitcoin briefly dipped below $63,000, with Bitcoin ETFs experiencing a $265 million daily outflow . Transfers below 1 BTC surged to 39,600 BTC in a single day—the highest daily level since November 2022, just 300 BTC below the amount moved in the immediate aftermath of the FTX collapse . CryptoQuant's Julio Moreno noted that "Bitcoin plebs had not moved this amount of BTC in a day since the FTX collapse" .

The attack has also reignited a long-running debate about self-custody versus centralized solutions. Nick Neuman, CEO of Bitcoin security company Casa, pushed back against claims that self-custody is "over," arguing that its distributed nature provides users time to react . Meanwhile, Bloomberg ETF analyst Eric Balchunas argued that Bitcoin ETFs may offer a safer and more convenient route for many investors, citing the longer operating history of the ETF industry .

However, others noted this should be viewed as a failure of a specific wallet provider rather than evidence that self-custody as a concept is fundamentally broken . A critical distinction remains: self-custody reduces reliance on centralized exchanges, but individual wallet implementations can and do fail.

What Affected Users Should Do Now

For Coldcard users, the message is clear and urgent. Galaxy's Alex Thorn warned on August 1: "The attack is ongoing—move your funds off Coldcard-generated addresses immediately if you have not done so" . Thorn added that every single-sig Coldcard address created after March 2021 will eventually be drained—"it is only a matter of time" .

Coinkite recommends the following steps:


  1. Install the fixed firmware before generating a replacement seed

  2. Generate a new seed on updated hardware

  3. Verify the new backup and receive address

  4. Send a small test transaction first

  5. Move the remaining balance only after confirming the test funds arrived 

Users should not rush, as mistakes in the recovery process could cause more damage than the vulnerability itself . Crucially, restoring the old seed to updated firmware or another wallet simply carries the weakness forward .

Arjun Mehta

Arjun Mehta

Senior Business Editor
MBA (Finance & Strategy) • 10 years experience

Arjun Mehta covers business, entrepreneurship, startups, and corporate developments shaping regional and global markets. His analytical reporting explains complex economic trends in a reader-friendly way.