Coldcard-related losses top $70M as Coinkite widens alert to newer models

AI Market Summary
A disclosed Coldcard firmware RNG regression (affecting multiple device generations below specified versions) is linked to ongoing seed brute-forcing, with reported thefts exceeding 1,080 BTC (~$70M) across ~1,200 wallets. While patches are available, remediation requires generating new seeds and migrating funds, extending operational risk. The episode pressures self-custody confidence and near-term security sentiment around bitcoin storage practices.
Impact level
● Medium
Affected assets
BTC/USDT-2.52%
AI Insight · BTC/USDTAI Insight
▼ Bearish
Trade now
⚠️ AI-generated insights are based on news content and are provided for informational purposes only. They do not constitute investment advice or represent the views of BingX. Investing involves risk. Please trade responsibly.
Losses tied to an exploit affecting Coldcard (@COLDCARDwallet) hardware wallets have climbed well beyond early estimates, with more than 1,080 bitcoin:native worth over $70 million reportedly siphoned from nearly 1,200 wallets, according to Galaxy Research and engineers at Block. Coinkite said the issue stems from a 2021 firmware bug that replaced the device's hardware random number generator with a weak software fallback, leaving wallet seeds vulnerable to brute-force attacks. The exposure affects Mk3 devices running 4.0.1–4.1.9, Mk4 and Mk5 devices below 5.6.0, and the Q below 1.5.0Q, unless the seed was generated using 50 or more dice rolls. Patches are now available, including the Mk3 4.2.0 update released Friday. Coinkite cautioned that installing updates alone does not secure existing wallets. Users need to generate a new seed and move funds to new addresses. Reports indicate the draining activity is continuing.