Hackers Exploit Coldcard Vulnerability to Steal Over $130 Million in Crypto

Hackers Exploit Coldcard Vulnerability to Steal Over $130 Million in Crypto

TL;DR

  • A firmware flaw in some Coldcard hardware wallets is being linked to a fast-moving theft campaign that has drained thousands of Bitcoin addresses and grown from about $70 million to roughly $88.6 million in on-chain losses, depending on the cutoff used by different researchers.
  • Researchers say attackers were able to reconstruct private keys from weak seed generation, meaning the issue affected wallets created from vulnerable firmware, not the Bitcoin protocol itself.
  • Coinkite has released patched firmware, but affected users are being told to create entirely new wallets and migrate funds, because updating alone does not fix seeds generated on compromised versions.

A major security failure in Coldcard hardware wallets has triggered one of the most significant self-custody thefts in recent memory, with researchers tracing a multi-wave attack campaign that siphoned tens of millions of dollars in Bitcoin from vulnerable wallets. The incident has raised fresh concerns about the security of offline storage devices and the dangers of trusting old seeds created on flawed firmware.

What happened

Galaxy Research first mapped a large sweep that drained 1,196 Bitcoin addresses in 41 minutes on July 30, taking 1,082.65 BTC worth about $70.2 million at the time. Later reports from the same broader investigation pushed the total higher as additional waves were identified, with one estimate reaching 1,367 BTC worth about $88.6 million across 4,585 addresses.

The attacker appears to have targeted the largest balances first, pulling more than $30 million in about 10 minutes before continuing to sweep smaller or dormant wallets. Some reporting also noted that the total losses continued to climb as more suspicious transactions were traced, with estimates ranging from the high-$70 million range to nearly $89 million depending on when the tally was taken.

The technical flaw

The vulnerability is tied to seed generation in certain Coldcard firmware versions, not to the Bitcoin network itself. According to Block’s engineering team, a coding error caused Coldcard firmware to silently fall back to a deterministic software random-number generator instead of the device’s intended hardware RNG, weakening the entropy used to create wallet seeds.

That matters because a weak seed can make the resulting private keys far more predictable than users would expect from a hardware wallet. In practical terms, attackers did not need physical access to the device; they could mathematically reconstruct keys created from affected firmware.

Which devices were affected

Early advisories suggested the issue was concentrated in Mk2 and Mk3 devices, particularly seeds generated on firmware versions 4.0.1 through 4.1.9. Later advisories expanded the scope to include some Mk4, Mk5, and Q devices created under older firmware builds before the patched releases.

Coinkite has since published fixed firmware, but the company and researchers emphasize that a software update alone is not enough for already compromised seeds. Wallets generated on affected firmware must be treated as unsafe, even if the device has since been updated.

Why the attack is so serious

This incident cuts to the heart of the hardware-wallet promise: that private keys are generated and stored in a way that keeps them isolated from attackers. In this case, the failure happened during the seed-creation process, which means the weakness could persist for years before being exploited.

That also explains why some of the drained wallets had remained untouched for long periods. Once the attacker identified vulnerable seeds, older dormant balances could be swept just as easily as newer ones.

What users are being told to do

Security researchers and Coinkite’s advisory guidance point to the same basic response: affected users should generate a brand-new wallet on fixed firmware or unaffected hardware and move their funds there. Several reports also stress that users should verify their backup, confirm the new receiving address on-device, and perform a small test transfer before moving the full balance.

The key point is that a patched wallet is not the same as a safe wallet if the original seed was created on vulnerable firmware. In that case, the old seed remains exposed and should no longer be trusted.

Broader implications for crypto security

The Coldcard incident is likely to have a lasting effect on the self-custody market because it shows that even respected offline devices can fail at the firmware layer. For many users, that will reinforce a hard lesson: cold storage is not the same as invulnerability.

It also highlights the importance of supply-chain trust, firmware audits, and cautious handling of long-lived wallets. For the crypto community, the breach is a reminder that security depends not just on keeping keys offline, but on making sure those keys were generated correctly in the first place.

What comes next

Researchers are still tracing the full scope of the theft, and the total may continue to change as additional wallet sweeps are identified on-chain. For now, the incident stands as a high-profile example of how a single flaw in wallet firmware can cascade into massive losses across thousands of addresses.


AndroGuider Team
Articles written by the AndroGuider team. We try to make them thorough and informational while being easy to read.
Hackers Exploit Coldcard Vulnerability to Steal Over $130 Million in Crypto Hackers Exploit Coldcard Vulnerability to Steal Over $130 Million in Crypto Reviewed by Randeotten on 8/04/2026 11:48:00 PM
Subscribe To Us

Get All The Latest Updates Delivered Straight To Your Inbox For Free!





Powered by Blogger.