Coldcard firmware flaw let attacker siphon 1,082 BTC before public alert
AI Market Summary
A long-running Coldcard firmware entropy flaw enabled offline key recreation and rapid theft of ~1,082.65 BTC from ~1,100 wallets before a public warning, underscoring hardware-wallet supply-chain/firmware risk. The incident can raise counterparty and custody concerns, prompt accelerated wallet migrations, and increase perceived operational risk for self-custody. Near term, it may pressure crypto risk appetite as investors reassess security assumptions around seed generation and device firmware.
Impact level
● High
Affected assets
BTC/USDT-1.10%
AI Insight · BTC/USDTAI Insight
▼ Bearish
Trade now
⚠️ AI-generated insights are based on news content and are provided for informational purposes only. They do not constitute investment advice or represent the views of BingX. Investing involves risk. Please trade responsibly.
A long-overlooked firmware weakness in Coldcard hardware wallets has led to one of the biggest recent Bitcoin thefts from hardware devices, with more than 1,082 BTC (about $70 million) taken from over 1,100 wallets before the manufacturer issued a public warning.
Galaxy Research said the attacker emptied 1,196 Bitcoin addresses between 01:10 and 01:51 UTC on July 30, draining about 1,082.65 BTC in a 41-minute burst. The sweep occurred nearly 30 hours before Coinkite warned users that certain Coldcard devices could be exposed.
Researchers believe the devices were not breached directly. Instead, the attacker likely reconstructed private keys offline by exploiting a flaw in how some Coldcard wallets generated recovery seed phrases. The affected set included wallets created on Coldcard Mk3 units running firmware versions 4.0.1 through 5.0.3, first released in March 2021.
Galaxy Research noted consistent transaction fingerprints: each withdrawal used the same unusually high 30 sat/vB fee and produced no change output. That pattern suggests the attacker already had the private keys and automated the drains.
Security researchers traced the root cause to a 2021 firmware update. Hardware wallets typically rely on a dedicated hardware random number generator to create recovery phrases. Block engineers found a coding error that unintentionally disabled hardware randomness on impacted devices, pushing key generation to a software-based random number generator that used more predictable inputs such as the device serial number and internal clock.
As a result, the effective strength of seed phrases on impacted Mk3 devices fell from the expected 128 bits of entropy to roughly 40 bits, making large-scale brute-force attacks feasible with modern computing power. Coinkite later broadened its warning to certain Mk4, Mk5 and Coldcard Q firmware versions, where entropy dropped to around 72 bits, while saying newer hardware architecture materially reduces overall risk.
After the theft, the stolen BTC was rapidly consolidated into several wallets. Researchers identified one address still holding more than 562 BTC, with other addresses containing 398 BTC, 89 BTC, and 32 BTC. None of the funds has moved since consolidation.
Coinkite urged anyone who generated a recovery phrase on affected firmware to immediately move funds into a newly created wallet generated using the latest firmware. The company added that users who enabled an additional BIP39 passphrase face significantly lower risk, as the extra passphrase provides another security layer beyond the compromised seed.
Security experts said the attacker likely precomputed millions of candidate wallet keys and waited for matching wallets to appear on the Bitcoin network. They warned additional exposed wallets could still be at risk if owners do not migrate their funds.