Coldcard Wallet Flaw Drains Nearly $89M in Bitcoin From 1,196+ Addresses

by priyanka.patel tech editor
Coldcard Wallet Flaw Drains Nearly $89M in Bitcoin From 1,196+ Addresses

A firmware flaw in Coinkite’s Coldcard hardware wallets has enabled attackers to drain approximately $88.6 million in Bitcoin from 4,585 addresses. The vulnerability, which existed since March 2021, allowed hackers to remotely reproduce predictable seed phrases and empty wallets without ever physically touching the devices.

The breach represents a systemic failure of the “cold storage” promise. For years, hardware wallets like the Coldcard were marketed as the gold standard of security because they keep private keys offline. However, a 2021 firmware bug effectively neutralized this isolation by making the seeds guessable through public data, such as serial numbers and clock readings.

The Three Waves of the Coldcard Drain

The theft unfolded in distinct phases, characterized by increasing scale and shifting tactics. According to CoinDesk, the initial wave occurred on July 30, where attackers drained 1,082.65 BTC—worth about $70.2 million—from 1,196 addresses in just 41 minutes.

exploit Hacker hacking privacy bitcoin Breaking Push cryptocurrency crime Coldcard bitcoin wallets
Photo: decrypt.co

This first surge was highly surgical. Chainalysis reported that the attacker prioritized high-value targets, stealing $30 million within the first ten minutes, including a single victim who lost $1.8 million. The efficiency of the attack suggested the use of automated tools; every transaction in the first wave used an identical hardcoded fee of 30 satoshis per virtual byte and left no change output.

Subsequent waves expanded the reach of the exploit. Galaxy Research later identified two additional waves, bringing the total observed losses to 1,367.05 BTC, or roughly $88.6 million, across 4,585 addresses. While the first wave averaged nearly one full coin per victim, the third wave was more fragmented, draining an average of just over a tenth of a bitcoin per victim across 1,912 addresses.

The RNG Failure: How Keys Became Predictable

The technical root of the crisis was a coding error in a March 2021 firmware integration. According to The Hacker News, the device was supposed to use an STM32 hardware random number generator (RNG) to create seed phrases. Instead, a firmware error routed seed generation to a deterministic software pseudorandom number generator (PRNG).

Coldcard Vulnerability Is Draining Bitcoin Wallets Right Now

This fallback generator relied on the device’s microcontroller identifier and system timing values. Because these values are not cryptographically secure, attackers could generate candidate seeds on their own machines, calculate the resulting Bitcoin addresses, and then check the public blockchain for matches. Once a match was found, the attacker possessed the private key and could move the funds.

The lack of randomness was severe. Coinkite estimates the effective entropy was roughly 40 bits on the Mk3 and about 72 bits on the Mk4, Mk5, and Q models. For comparison, a standard 12-word BIP-39 seed requires 128 bits of entropy.

Victim Impact and the “Safety Deposit Box” Paradox

The attack underscores a terrifying reality for long-term holders: physical security is irrelevant if the underlying mathematics are flawed.

Hacker facing screens with lines of code (Boitumelo/Unsplash)
Photo: CoinDesk

This “remote drain” has triggered a behavioral shift in the community. Decrypt reports an unusual reversal of the not your keys, not your coins mantra, as panicked users move their assets back to centralized exchanges like Coinbase or Binance to escape the vulnerable hardware seeds.

Galaxy’s Alex Thorn described the sweeps as deliberate and likely LLM-orchestrated, warning that every single-signature Coldcard address created after the March 2021 flaw will eventually be drained. Thorn noted that the stolen coins had an average dormancy of 3.18 years, confirming that the attackers specifically targeted long-term “HODLers.”

Coinkite’s Response and Recovery Path

Coinkite has released a software update to protect new wallets and contacted affected customers via email. However, the company emphasized that the only way to secure funds is to generate a completely new seed using the updated firmware and migrate the assets.

Coldcard Wallet Flaw Drains Nearly $89M in Bitcoin From 1,196+ Addresses
Photo: Foxbusiness
  • Unaffected Products: The TAPSIGNER, OPENDIME, and SATSCARD products use different codebases and are not at risk.
  • Partial Mitigation: Seeds supplemented with at least 50 independent dice rolls are not considered at risk from this specific flaw.
  • Passphrase Warning: While a strong BIP-39 passphrase makes exploitation harder, Coinkite still recommends a full seed migration.

The scale of the operation has also drawn scrutiny toward the manufacturer’s size. Bloomberg analyst Eric Balchunas noted that Coinkite reportedly has a staff of only around five people, a figure he suggested is strikingly disproportionate to the amount of capital the products protect.

The incident leaves a lingering uncertainty regarding the identity of the attacker, who remains unnamed. Galaxy Research has flagged roughly 600 suspected attacker-controlled addresses to federal investigators and compliance firms, but the stolen funds currently remain parked in those addresses.

Ultimately, the Coldcard exploit proves that the most dangerous vulnerability in cryptocurrency is not a hacked exchange or a stolen laptop, but a silent failure in the very tools designed to provide absolute autonomy.

You may also like