Skip to main content

Hardware Wallets Expose Bitcoin Holders to Massive Losses After Firmware Flaw Enables Remote Drains

Importance Critical

A critical firmware flaw in Coldcard hardware wallets has led to the remote draining of over $70 million in Bitcoin (BTC). Attackers exploited weak randomness in seed phrase generation on affected devices, allowing them to reconstruct private keys without any physical access.

According to Coinkite, the manufacturer of Coldcard, the error caused some devices to generate recovery seeds using a software-based source of randomness instead of the built-in hardware random-number generator. This made the resulting private keys significantly easier to predict.

The issue originated in firmware released in March 2021. While installing newer firmware resolves the underlying bug, it does not secure recovery seeds that were generated on affected devices. Galaxy Research tracked the sweep across 1,196 addresses totaling 1,082.65 BTC in roughly 41 minutes, nearly doubling earlier loss estimates of around $38 million.

Many compromised wallets had stayed inactive for years, making them particularly vulnerable to the predictable seed flaw in models shipped with the buggy firmware. Coinkite acknowledged the issue and released emergency firmware patches to address the randomness problem across multiple device versions.

Binance founder Changpeng Zhao (CZ) commented, “Even hardware wallets can have bugs, even old wallets with a long history can have bugs. How to mitigate? Split your funds in a few wallets maybe? This has a different set of risks. Nothing is 100%. Stay informed. Stay SAFU.”

The incident underscores ongoing risks in self-custody solutions despite their offline design and prompts broader discussions on wallet diversification strategies.

Source: https://dailyhodl.com/2026/08/02/hardware-wallets-expose-bitcoin-holders-to-massive-losses-after-firmware-flaw-enables-remote-drains/