Skip to main content

Coldcard Firmware Flaw Exposed Bitcoin Wallets: Exploit Drains ~$70M

Importance Critical

On July 30, an attacker exploited weak seed generation in certain Coldcard hardware wallets, stealing bitcoin worth roughly tens of millions from hundreds of addresses. Galaxy Research linked the theft to as many as 1,196 addresses and 1,083 bitcoin, valued at nearly $70 million, with the core theft occurring in a 25-minute burst. Final figures may change as tracing continues.

The affected wallets belonged largely to long-term holders who generated seeds using Coldcard devices running vulnerable firmware released from March 2021 onward. The attacker moved rapidly, paid elevated fixed fees, and emptied addresses completely, suggesting an automated operation using a prepared list of private keys. The theft was not caused by phishing, malware, or physical device theft but by a firmware error that weakened randomness during seed generation.

Coldcard devices were supposed to use a hardware random number generator. However, during a 2021 software-library migration, two random-number functions became confused. A configuration setting disabled the default hardware path, and seed generation silently shifted to a weak software fallback that relied on predictable device information such as chip identifiers and startup timing. Coinkite estimated the effective search space for vulnerable Mk3 seeds at about 40 bits instead of the intended 128 bits. Later models (Mk4, Q, Mk5) got some randomness from a secure element but still had an estimated 72 bits of entropy, below the 128-bit standard.

Coinkite released security advisories and corrected firmware. The company said users who generated seeds on affected firmware should create a completely new seed using a fixed version and transfer bitcoin to addresses controlled by that seed. Installing the update alone is not enough; the old seed remains weak permanently. Fixed releases include Mk3 version 4.2.0 or later, Mk4 and Mk5 version 5.6.0 or later, and Q version 1.5.0Q or later. Tapsigner, Opendime, and Satscard were not affected.

Some users were protected by adding at least 50 rolls of a fair die during seed generation, using a strong BIP-39 passphrase, or using multisignature wallets where the Coldcard seed was only one part of the signing arrangement. However, many victims followed standard security advice and were unaware of the flaw.

Coinkite CEO Rodolfo Novak apologized on July 31 and accepted full responsibility. He said the hotfix secures newly created seeds but cannot repair existing weak seeds. Coinkite will publish a full technical account and assist affected users with police reports and insurance claims. Novak also warned that AI tools can scan old public code for hidden weaknesses, though no evidence has established how the flaw was discovered.

The attacker’s identity remains unknown, and stolen bitcoin could move at any time. Investigators are still determining how many vulnerable seeds were generated and how much bitcoin remains exposed. Coinkite purges customer records after 120 days, so it cannot reach out to all affected buyers. Users with seeds generated on vulnerable firmware without strong independent entropy, a passphrase, or multisig protection should treat those seeds as compromised and move funds carefully to a newly generated wallet.

Source: https://news.bitcoin.com/featured/the-coldcard-exploit-explained-who-lost-bitcoin-and-whos-at-risk/