NewsCryptoColdcard Bitcoin Wallet Exploit Exceeds $100 Million Across Three Coordinated Attack Waves

Coldcard Bitcoin Wallet Exploit Exceeds $100 Million Across Three Coordinated Attack Waves

Author: CryptoMeter io·

Key Takeaways

  • A firmware vulnerability in Coldcard hardware wallets enabled attackers to steal over $100 million in Bitcoin across three coordinated attack waves.
  • The flaw originated in Coldcard's random number generation process, allowing attackers to reconstruct wallet seed phrases and derive private keys without physical device access.
  • The initial attack on July 30 drained more than 1,000 wallets in under an hour, with subsequent waves affecting wallets created using compromised firmware versions spanning several years.
  • Coinkite has released firmware updates but advises affected users to migrate funds to wallets with freshly generated recovery phrases, as updating alone does not secure previously exposed seeds.
  • The incident has intensified calls across the hardware wallet industry for independent third-party audits of seed generation code, while competing manufacturers Ledger and Trezor have not been linked to the vulnerability.
Coldcard Bitcoin Wallet Exploit Exceeds $100 Million Across Three Coordinated Attack Waves

A security vulnerability in Coldcard hardware wallets has resulted in one of the most significant Bitcoin wallet breaches ever recorded, with confirmed losses now surpassing $100 million following three coordinated waves of attacks. Coldcard, a Bitcoin-only hardware wallet produced by Coinkite, is widely used among security-conscious and privacy-focused Bitcoin holders, making the breach particularly significant for the self-custody community.

Security researchers at Galaxy reported that attackers exploited a firmware flaw affecting wallet seed generation, enabling them to systematically identify and drain vulnerable Bitcoin wallets.

The initial attack wave occurred on July 30, when attackers emptied over 1,000 wallets in under an hour. Subsequent waves drove total losses past the $100 million threshold as additional compromised wallets were identified and emptied. The attackers focused primarily on wallets created using affected firmware versions spanning several years, underscoring the enduring dangers associated with cryptographic implementation flaws.

How the Vulnerability Worked

According to Galaxy's analysis, the vulnerability stemmed from a defect in Coldcard's random number generation process, which is used to create wallet recovery seeds. Rather than generating sufficiently unpredictable seed phrases, the vulnerable firmware produced entropy that attackers could feasibly reconstruct given significant computational resources. The flaw echoes earlier cryptocurrency security failures tied to weak random number generation, including a 2013 vulnerability in Android Bitcoin wallets that similarly allowed attackers to predict private keys.

Consequently, hackers were able to derive private keys without resorting to phishing, malware installation, or physical access to the hardware devices. Researchers described the incident as especially severe because it compromised one of the foundational security assumptions underlying hardware wallets — that a device isolated from networked systems can reliably generate cryptographic keys no remote adversary can reproduce.

The breach impacted multiple generations of Coldcard devices that had wallets created using the compromised firmware. However, wallets generated with updated firmware and newly created seed phrases are not believed to be at risk.

Industry Response

Coinkite acknowledged the vulnerability and issued firmware updates while urging affected users to immediately migrate their funds to wallets created with fresh recovery phrases. Merely updating the device does not protect wallets originally generated with vulnerable firmware, as the compromised seed phrase remains exposed.

The breach has reignited debate within the cryptocurrency industry regarding hardware wallet security and the rigor of software auditing. While hardware wallets are still regarded as one of the safest methods for self-custody, the incident illustrates that implementation bugs can produce catastrophic consequences when they affect key generation. Competing hardware wallet manufacturers such as Ledger and Trezor have not been linked to the vulnerability, but the event has intensified calls for independent third-party audits of seed generation code across the broader hardware wallet industry.

Security experts continue to monitor blockchain activity for further thefts, cautioning that additional vulnerable wallets may remain at risk for users who have not yet migrated their funds. Users who created Coldcard wallets during the affected period are advised to verify their firmware version and move funds to newly generated wallets as a precautionary measure.