Coldcard Hack May Put Up to $114 Million at Risk as More Wallets Get Swept
AI Market Summary
Reports of an ongoing Coldcard exploit tied to weak entropy in older Mk3 seed generation raise renewed operational and custody risk for Bitcoin holders. Potential exposure is estimated near $114M as additional wallet sweeps are discussed, though attribution and totals remain unconfirmed. The incident pressures confidence in hardware wallet security assumptions and may temporarily increase precautionary key migrations and scrutiny of self-custody practices.
Impact level
● Medium
Affected assets
BTC/USDT+1.09%
AI Insight · BTC/USDTAI Insight
▼ Bearish
Trade now
⚠️ AI-generated insights are based on news content and are provided for informational purposes only. They do not constitute investment advice or represent the views of BingX. Investing involves risk. Please trade responsibly.
A suspected exploit affecting Coldcard, the Bitcoin hardware wallet made by Coinkite, is being linked to potential losses approaching $114 million, as signs of a possible fourth wave of wallet "sweeps" surface. The case remains fluid, with investigators still tracking movements and no definitive attribution or final loss total confirmed.
The issue traces back to how seed phrases were generated on certain older Coldcard devices. Coinkite has issued a warning to Coldcard Mk3 users, urging them to review whether their device used affected firmware and to migrate funds to a newly generated, securely created seed if they may be exposed.
A technical review cited in reporting points to a weakness in entropy: a predictable random-number-generator fallback combined with a 32-bit reseed in Coldcard firmware. In practical terms, weaker randomness can make private keys more guessable, increasing the risk that an attacker can recreate wallet keys and drain funds.
The $114 million figure is being presented as an estimate of potential exposure rather than a confirmed accounting of stolen assets. According to CoinDesk, losses could near that level as another sweep of vulnerable wallets appears to be underway. Because the outflows have occurred in waves, the running total can change as more affected addresses are identified or drained; recoveries, freezes, or misclassified transfers could also push the final number higher or lower.
For Coldcard users, the immediate priority is determining whether their seed was generated under the impacted conditions. Coinkite's guidance following a reported theft of 594 BTC directs Mk3 holders to verify their device generation and move funds if there is any doubt.
Beyond Coldcard, the episode underscores a core self-custody tradeoff: holding your own keys reduces counterparty risk but concentrates operational risk in device design and firmware implementation. Recent industry incidents, including a separate warning from ZeroStack after an $82.5 million loss, have reinforced how security details can translate directly into material financial impact.
Disclaimer: This content is for informational purposes only and does not constitute financial or investment advice. Cryptocurrency and digital asset markets involve significant risk. Conduct your own research before making decisions.