NewsCryptoColdcard Bitcoin Theft Could Reach $132M as 15+ Attackers Exploit Vulnerable Firmware

Coldcard Bitcoin Theft Could Reach $132M as 15+ Attackers Exploit Vulnerable Firmware

Author: Crypto Adventure·

Key Takeaways

  • Galaxy Research has high confidence that 1,596 BTC was stolen across roughly 7,300 addresses, with a suspected fourth wave potentially bringing the total to 2,055 BTC valued at approximately $132 million.
  • Analyst Alex Thorn estimates that at least 15 separate attackers are exploiting seeds generated on affected Coldcard devices, replacing an earlier assessment that attributed the thefts to a single operator.
  • The vulnerability allows affected firmware to fall back to a deterministic MicroPython random-number generator instead of the intended STM32 hardware RNG, with Mk2 and Mk3 versions adding no cryptographic entropy to that fallback path.
  • Bitcoin developer James O'Beirne disclosed that he warned Coinkite about random-number generation concerns during a May 2025 firmware audit, but the company reportedly dismissed the warning.
  • The vulnerability disclosure prompted a surge in wallet migration activity, pushing daily active Bitcoin addresses from approximately 645,000 to nearly one million — the highest level recorded since December 2024.
Coldcard Bitcoin Theft Could Reach $132M as 15+ Attackers Exploit Vulnerable Firmware

Bitcoin thefts linked to Coldcard hardware wallets may have reached 2,055 BTC — approximately $132 million at current prices — as multiple attackers compete to drain wallets created with vulnerable firmware, according to Galaxy Research. Coldcard devices, manufactured by Coinkite, are widely used Bitcoin-only hardware wallets marketed for their air-gapped design and self-custody features, making the scale of the exploit particularly notable within the hardware wallet ecosystem.

The research firm says it has high confidence that three major waves of theft alongside 14 smaller incidents resulted in the removal of 1,596 BTC from roughly 7,300 addresses. A suspected fourth wave, if confirmed, would bring the total to 2,055 BTC across more than 7,700 addresses. However, Galaxy has not yet collected sufficient victim reports to classify that group with the same level of certainty.

At Least 15 Attackers Exploiting Coldcard-Generated Seeds

Galaxy Research analyst Alex Thorn now estimates that at least 15 distinct attackers are exploiting seeds generated on affected Coldcard devices. This assessment replaces an earlier theory that a single operator was behind the coordinated wallet drains.

The fragmented nature of the activity has made attribution significantly more difficult, as each attacker may employ different consolidation addresses, transaction structures, and spending patterns. Galaxy has asked affected users to privately submit their wallet addresses so researchers can distinguish legitimate fund migrations from actual thefts and provide cleaner data to law enforcement.

The documented total has risen sharply since Block and Coinkite initially disclosed the vulnerability, when 1,083 BTC had been identified. A subsequent third suspected wave saw another 207.7294 BTC removed before smaller attacker clusters and a possible fourth wave expanded the estimate further.

As of Galaxy's latest analysis, the majority of suspected stolen Bitcoin — including all coins attributed to the first three major waves — remained unmoved.

Developer's 2025 RNG Warning Was Reportedly Dismissed

Bitcoin developer James O'Beirne disclosed that he raised concerns about Coldcard's random-number generation during a May 2025 firmware audit, more than a year before the vulnerability became public knowledge.

O'Beirne traced the seed generation process to the libngu cryptographic library and questioned whether its random function was properly receiving secure hardware entropy. He stated that Coinkite dismissed his warning on the grounds that a serious defect would have already been discovered. Coinkite has not publicly confirmed O'Beirne's account of the exchange.

Block's subsequent technical investigation determined that affected firmware could fall back to a deterministic MicroPython generator rather than utilizing the STM32 hardware random-number generator as intended. Random-number generation flaws are especially critical in cryptocurrency systems because predictable or low-entropy seed generation can allow attackers to reconstruct private keys without compromising the device physically. Mk2 and Mk3 firmware versions added no cryptographic entropy to that fallback path, while newer models retained only 32 bits of entropy during secure-element reseeding.

Coinkite's updated advisory covers affected firmware versions for the Mk2, Mk3, Mk4, Mk5, and Q models and provides patched releases for each supported device.

Wallet Migration Drives Bitcoin Network Activity to 2024 High

The vulnerability disclosure triggered a large-scale migration of Bitcoin into replacement wallets and, in some instances, centralized exchanges.

Daily active Bitcoin addresses surged from approximately 645,000 on July 30 to nearly one million on July 31 — the highest level recorded since December 2024. Transfers of amounts below 1 BTC totaled roughly 39,600 BTC as smaller holders responded to the security warning.

CryptoQuant analyst JA Maartunn separately tracked 77,402 BTC moving from older UTXO age bands following the public disclosure, suggesting that long-dormant holders also rotated their funds.

Affected users are advised to install the patched firmware, generate an entirely new seed, verify the receiving address, send a small test transaction, and then transfer the remaining balance. Importing an old recovery phrase into a different device does not eliminate the exposure.