Galaxy Digital Reports $70 Million Drained in Coldcard Bitcoin Wallet Exploit
Researchers at Galaxy Digital have reported that approximately $70 million in Bitcoin was stolen due to an exploit in the popular Coldcard hardware wallet. The attack was made possible by a firmware bug that significantly reduced the randomness of the wallet’s seed phrase generation.
According to Galaxy, most of the stolen funds were taken in under an hour. The initial attack spans six blocks and 41 minutes, with transactions broadcast in batches. The losses are mostly from addresses holding between 1 and 50 BTC, indicating individual self-custody rather than institutional or exchange holdings. Galaxy warned that further attacks could occur if users do not migrate their funds from affected Coldcard-generated addresses.
Coinkite, the company behind Coldcard, has taken full responsibility for the firmware bug and apologized to affected users. They have released emergency firmware updates for all affected models: version 4.2.0 or later for Mk3, 5.6.0 or later for Mk4 and Mk5, and 1.5.0Q or later for the Coldcard Q. These updates remove the vulnerable software fallback path and ensure that new seeds are generated using the hardware’s true random number generator.
It is critical to note that a firmware update alone does not secure existing seeds. Users must generate an entirely new recovery phrase on the fixed firmware and migrate their Bitcoin to the new addresses.