READ. SCROLL. LISTEN.

Original briefings. Zero spin.

Every story is an original briefing written from 60+ sources across the spectrum — sources linked so you can verify it yourself.

← Back to headlines

Coldcard Hardware Wallets Hit by $130 Million Bitcoin Theft Tied to 2021 Firmware Bug

Coldcard Hardware Wallets Hit by $130 Million Bitcoin Theft Tied to 2021 Firmware Bug
A five-year-old firmware bug in Coinkite's Coldcard hardware wallet let attackers predict supposedly random seed phrases, and at least 15 different hackers have swept roughly 2,055 BTC, worth about $130 million, from more than 7,700 addresses. Coinkite has patched the bug, but the fix does nothing for wallets that already generated a compromised seed, so anyone who hasn't moved their coins is still exposed.

A bug buried in one line of code from March 2021 has turned one of Bitcoin's most trusted offline storage devices into an open vault.

Hackers have stolen roughly $130 million in Bitcoin from users of the Coldcard hardware wallet, made by Canadian manufacturer Coinkite, according to Galaxy Research. The firm says it has confirmed 1,596 BTC, worth more than $100 million, stolen from about 7,300 addresses across three coordinated waves plus 14 smaller incidents. A suspected fourth wave, held with "medium-high confidence" but not yet confirmed by victim reports, would push the total to 2,055 BTC, close to $130 million, across more than 7,700 addresses, Galaxy Research's Head of Firmwide Research Alex Thorn said.

Coldcard wallets are supposed to be about as safe as crypto storage gets. They're never connected to the internet. The private key, or seed phrase, that controls a user's Bitcoin lives entirely on the offline device. No internet connection is supposed to mean no remote attack surface.

That theory collapsed once security researchers at Block traced the problem to a single firmware change made on March 1, 2021. That change caused Coldcard devices to fall back on a software-based random number generator instead of the hardware's dedicated randomness source when creating new seed phrases. The seeds that came out the other end had far less randomness than they were supposed to have.

Block's engineers estimated the effective search space for Mk3 devices had collapsed to roughly 40 bits under some conditions, and stayed below 73.3 bits for Mk4, Mk5, and Coldcard Q models, according to CoinMarketCap. The devices were designed for 128-bit security. An attacker who can pin down a device's unique identifier, its timer state, and its prior random-number history can reconstruct candidate seeds and check them directly against public blockchain data. No physical access, no internet connection on the victim's end required.

In practice, that meant hackers didn't need to break into anyone's safe. They just needed to figure out how the locks were made, then cut master keys and go looking for which doors they opened.

The first confirmed sweep happened on July 30, when an attacker drained 1,082.65 BTC from 1,196 addresses in 41 minutes, according to Galaxy Research's timeline reported by CoinMarketCap. Two more waves followed at roughly 27-hour intervals. What started as a handful of coordinated operators has since fractured into something messier. The Crypto Times reported that Thorn now estimates at least 15 different attackers are independently working through the remaining vulnerable wallets, a shift from a few big coordinated sweeps to what he described as an open scramble of copycats and opportunists picking off whatever balances remain, down to small amounts.

This is no longer a single breach that ends once the original attacker is done. It's now a distributed, ongoing hunt, and every day an unmigrated wallet sits exposed is another day it can be found.

One victim, Jonathan Goodman, said he lost $1.6 million despite doing everything security guides tell people to do. "I never shared my seed phrase with anybody. My devices never touched the internet. Everything was kept in multiple safes and safety deposit boxes," he wrote on X, adding that none of it mattered because of "one line in their code from 2021."

Coinkite published an advisory on July 30 and updated it August 1, alerting customers to the flaw and urging immediate firmware updates, according to TechCrunch. The company has released patched firmware for all affected models, covering Coldcard Mk2 and Mk3 before version 4.2.0, Mk4 and Mk5 before 5.6.0, Coldcard Q before 1.5.0Q, and related Edge builds, per CoinMarketCap. Coinkite says it has also destroyed remaining inventory that was manufactured with the vulnerable firmware.

The catch is more important than the patch itself: updating the firmware does nothing to protect a seed phrase that was already generated on a vulnerable version. If your seed was created before the fix, it's already crackable, patch or no patch. Coinkite is telling users they must generate an entirely new seed on updated hardware and physically move their Bitcoin to new addresses controlled by that new seed. Anyone who just updates their firmware and keeps using their old seed phrase is still sitting on a compromised key.

Coinkite did not respond to TechCrunch's request for comment. Galaxy Research says it continues to pass victim reports and attacker information to law enforcement, though no arrests or criminal charges have been announced. Total loss estimates have climbed steadily since the flaw became public, starting around $38 million before rising past $100 million and now toward $130 million, according to The Crypto Times. Whether that number keeps climbing depends on how many Coldcard owners still haven't checked which firmware version created their seed.

Sources used for this briefing

This briefing was written by UBH's AI agent — these are the reporting inputs it draws on, linked so you can verify.

center-left
TechCrunchHackers steal over $130M by exploiting bug in offline hardware wallets
unknown
coingapeRipple CTO Emeritus Decodes Coldcard Bitcoin Hack As Losses Exceed $100 Million
unknown
coinmarketcapColdcard Hack Tops $100M as Galaxy Flags Possible 4th Wave | CoinMarketCap
unknown
cryptotimes.io15 Attackers Exploit Coldcard Hack as Losses Approach $130M - The Crypto Times