Bitcoin ColdCard Wallet Exploit Spreads to 4,585 Addresses, Losses Near $90 Million
Key Takeaways
- •Attackers have stolen approximately 1,367 BTC worth nearly $89 million across three coordinated waves targeting ColdCard wallets created with vulnerable firmware.
- •The exploit originates from a firmware build configuration flaw that caused predictable seed generation using hardware values instead of the device's dedicated random-number generator.
- •The third and latest wave uses a more sophisticated approach, routing stolen funds to separate pay-to-witness-script-hash addresses, which researchers say could complicate blockchain tracing.
- •Users who created wallets with the affected firmware remain vulnerable even if their devices were subsequently updated, exposing a persistent supply-chain risk in self-custody setups.
- •Galaxy Research warns that the growing number of affected addresses indicates attackers are still identifying new vulnerable wallets, meaning total losses could increase further.

Losses tied to the ColdCard hardware wallet vulnerability have reached nearly $89 million, with attackers expanding the campaign to 4,585 Bitcoin addresses across three coordinated waves of theft, according to Galaxy Research.
The most recent sweep raised the total stolen to 1,367 BTC, up from approximately 1,083 BTC ($70 million) reported just one day earlier.
The attack first surfaced on July 30, when hackers drained roughly 594 BTC from nearly 500 wallets in what initially appeared to be an isolated incident. Within hours, a substantially larger second wave compromised more than 1,196 wallets, pushing cumulative losses past $70 million. This second wave revealed that the exploit targets wallets created with vulnerable versions of ColdCard firmware rather than the physical devices themselves.
A newly identified third wave indicates the campaign remains active and evolving. Unlike the earlier attacks, which consolidated stolen bitcoin into a small number of collector wallets, the latest operation routes funds from each victim to separate destination addresses stored in pay-to-witness-script-hash (P2WSH) outputs. Researchers note that this more sophisticated approach could complicate blockchain analysis.
According to researchers, the exploit originates from a firmware build configuration that caused affected ColdCard devices to generate wallet seeds using predictable hardware values instead of the device's dedicated hardware random-number generator. Hardware wallets depend on high-quality entropy from these generators to ensure that private keys cannot be guessed or reproduced by third parties. Because every Bitcoin private key is derived from that seed, attackers capable of recreating it can derive the same wallet and sweep funds without ever physically accessing the device.
The incident ranks among the largest attacks ever directed at Bitcoin self-custody through cryptographic key generation, as opposed to malware, phishing, or exchange breaches. ColdCard, manufactured by Coinkite, is a widely used hardware wallet among Bitcoin users who practice self-custody — managing their own private keys rather than entrusting funds to exchanges. The exploit has exposed a distinctive supply-chain risk: users who securely maintained offline wallets for years remained vulnerable if those wallets were originally created using the affected firmware, even if the device was subsequently updated.
Galaxy Research cautions that the increasing number of affected addresses suggests attackers continue to identify new vulnerable wallets, meaning total losses could rise further as additional weak seeds are reconstructed and exploited.