A firmware flaw in popular Coldcard Bitcoin hardware wallets allowed attackers to drain tens of millions of dollars in cryptocurrency from hundreds of wallets without ever touching the devices, according to blockchain researchers and the manufacturer.
Galaxy Research estimates that more than 1,000 bitcoin, valued at roughly $70 million in one major tally and higher in later counts that reached about $88 million, was swept from addresses linked to vulnerable Coldcard seeds. The largest coordinated wave occurred in a roughly 41-minute window on July 30, with earlier reports focusing on about 594 bitcoin (around $38 million at the time) moved from roughly 500 single-signature wallets in about 25 minutes.The vulnerability stems from a build error introduced in firmware around March 2021.
Affected devices, particularly certain Coldcard Mk2 and Mk3 units running versions 4.0.1 through 4.1.9, fell back to a predictable software-based random number generator instead of the intended hardware true random number generator.
This sharply reduced the entropy of device-generated recovery seeds. Coinkite, the Toronto-based maker of Coldcard, estimated the effective search space on the most affected Mk3 devices at roughly 40 bits instead of the expected 128 bits. Seeds generated on Mk4, Mk5, and Q models before fixed firmware also had reduced entropy of about 72 bits.
Attackers reconstructed the weak seeds offline, matched them to on-chain addresses, and transferred funds. Many targeted wallets had been dormant for years. No physical access to the devices was required.Coinkite issued a security advisory and released patched firmware.
Fixed versions include 4.2.0 or later for Mk2 and Mk3 devices, 5.6.0 or later for standard Mk4 and Mk5, 1.5.0Q or later for the standard Q model, and corresponding Edge releases. The company stressed that simply updating firmware does not secure an already-generated weak seed.
Users must create an entirely new seed on fixed hardware and carefully migrate funds, preferably after testing with a small amount.Seeds generated with at least 50 independent private dice rolls or protected by a strong, unique BIP-39 passphrase face significantly lower risk from this specific issue, according to Coinkite.
The company noted that its open-source firmware may have been reviewed with artificial intelligence tools, though it said its own prior AI code review did not detect the problem.The incident has renewed debate about the risks of self-custody even with air-gapped hardware wallets.
Security researchers and industry figures have urged users to verify their setups and consider diversifying storage practices.Coinkite continues to investigate and has advised all potentially affected users to follow its migration guidance immediately.