NewsCryptoColdcard Bitcoin Hack: Victims Report Median Loss of 1 BTC as Theft Tops $111 Million

Coldcard Bitcoin Hack: Victims Report Median Loss of 1 BTC as Theft Tops $111 Million

Author: Bitcoin Magazine·

Key Takeaways

  • A firmware bug in Coldcard Mk3 devices, present since version 4.0.1 released in March 2021, caused seed generation to rely on a weak software pseudorandom number generator instead of the secure hardware-based generator, allowing attackers to reconstruct users' seed phrases.
  • Galaxy Research's review of 250 victim reports found that 88% of stolen funds had been dormant for at least one year, with the typical pilfered coin sitting untouched for approximately 3.5 years.
  • Individual victims reported a median loss of 1.022 Bitcoin and an average loss of 4.04 Bitcoin, with the single largest reported loss reaching 58.97 coins.
  • Galaxy Research has confirmed $111 million stolen so far but stated that total losses will likely exceed $130 million as additional stolen coins are verified.
  • Following the breach, many cautious investors have relocated their Bitcoin to alternative storage solutions including cryptocurrency exchanges, reversing their original decision to use hardware wallets for self-custody.
Coldcard Bitcoin Hack: Victims Report Median Loss of 1 BTC as Theft Tops $111 Million

New analysis of Bitcoin theft reports linked to the Coldcard hardware wallet breach reveals that stolen funds overwhelmingly came from long-dormant wallets, with victims reporting a median loss exceeding one full coin.

Data posted on X by Galaxy Research's Alex Thorn examined 250 victim reports. The findings showed that the typical stolen coin had sat untouched for approximately 3.5 years, and 88% of pilfered funds were at least one year old — a pattern consistent with the profile of long-term holders who purchased hardware wallets specifically for cold storage and rarely touched their funds.

Measured by address, losses ranged from a median of 0.014 Bitcoin to a mean of 0.212 Bitcoin. Individual victims, however, reported a median loss of 1.022 Bitcoin and an average of 4.04 Bitcoin — with one holder losing as much as 58.97 coins.

Hackers began by taking over $35 million in Bitcoin from wallets on Thursday of last week. Coinkite, the manufacturer of Coldcard, confirmed that a firmware bug in Coldcard Mk3 devices — originating with version 4.0.1 released in March 2021 — caused seed generation to fall back to a weak software pseudorandom number generator instead of the hardware-based true random number generator. This vulnerability effectively allowed attackers to guess users' seed phrases, the recovery keys that grant full control over a Bitcoin wallet.

The vulnerability's March 2021 origin means affected devices may have been generating insecure seeds for over three years across multiple firmware releases. The theft persisted throughout the weekend as Coinkite and other Bitcoin community members urged Coldcard users to immediately move their funds to secure alternatives.

Galaxy Research stated Friday that $111 million has been confirmed stolen, though the figure could rise significantly as the investigation continues.

"We have many more coins we are vetting for confirmation — we think total losses likely exceed $130 million," the firm wrote on X (https://x.com/glxyresearch/status/2085748513015488758).

Since the attack, cautious investors have been relocating their coins to other storage solutions, including cryptocurrency exchanges — a notable reversal for users who had adopted hardware wallets specifically to avoid third-party custody.

Coinkite said in a statement this week that the software bug "silently went unnoticed" and "its potential impact grew with every release" of its products. Days after the initial hack, the company urged all investors to update their firmware or move their funds off the affected hardware wallet.

Source: Bitcoin Magazine by Mathew Di Salvo.