$40M in Bitcoin Stolen After Coldcard Wallet Firmware Flaw Exposed

AI Market Summary
Reports of ~$40M in BTC drained from ~500 Coldcard wallets via an alleged key-generation firmware entropy flaw highlight acute hardware-wallet and supply-chain risk. Rapid, coordinated outflows and subsequent routing through high-obfuscation mixers can raise near-term perceived counterparty and custody risk across crypto, potentially dampening risk appetite and increasing focus on self-custody verification, firmware provenance, and on-chain monitoring.
Impact level
● High
Affected assets
BTC/USDT-2.74%
AI Insight · BTC/USDTAI Insight
▼ Bearish
Trade now
⚠️ AI-generated insights are based on news content and are provided for informational purposes only. They do not constitute investment advice or represent the views of BingX. Investing involves risk. Please trade responsibly.
An attacker reportedly siphoned roughly $40 million worth of BTC from about 500 Coldcard wallets after a critical compromise involving the device's key-generation firmware. Blockchain analysts say the affected addresses were drained in a coordinated sweep spanning about 25 minutes. The exploit is believed to have leveraged an entropy weakness in the hardware's derivation-path logic, allowing the attacker to reconstruct private keys. On-chain monitoring shows the funds were quickly routed into high-obfuscation mixing services.