Key Takeaways
A firmware bug dating back to 2021 weakened recovery seed generation, allowing attackers to reconstruct private keys and steal 1,367 BTC.
Installing the latest firmware is not enough; affected users must create a brand-new recovery seed and transfer their bitcoin.
Security researchers warn more thefts are possible as the vulnerability is now public and attackers continue targeting vulnerable wallets.
What Triggered the Coldcard Wallet Crisis?
A serious security problem in Coldcard hardware wallets has been linked to the theft of more than 1,300 BTC, worth about $89 million. Security experts say it is one of the biggest hardware wallet incidents ever reported. Users who may be affected are being told to move their bitcoin to new wallets as soon as possible.
According to the latest findings from Galaxy Research, attackers have stolen 1,367 BTC from 4,585 wallet addresses in three waves of attacks. The first attack happened on July 30, when 1,082.65 BTC was drained from 1,196 wallets in just 41 minutes. Later attacks targeted more wallets, pushing the total losses to nearly $89 million.
Analyses say the latest wave targeted much smaller wallets than before, suggesting that the attacker has moved beyond high-value victims and is now sweeping whatever vulnerable wallets remain.
Researchers say the problem was caused by a software bug that has existed since March 2021. Instead of using the wallet's hardware random number generator to create secure recovery seeds, affected devices used a weaker software-based random number generator. This made some wallet recovery phrases much easier to guess than they should have been.
Hardware wallets are designed to generate recovery seed phrases using a true hardware random number generator, making the resulting private keys practically impossible to guess.
However, engineers from Block discovered that a software error caused affected Coldcard devices to use a predictable software random number generator instead.
According to the technical analysis, a coding mistake caused the wallet software to bypass the hardware random number generator and rely on a deterministic pseudorandom generator seeded with predictable values such as the device's serial number and timing information.
Researchers estimate that this reduced the security of wallet seeds dramatically. For affected Mk3 devices, the effective entropy dropped to roughly 40 bits, compared with the expected 128 bits used for a standard 12-word BIP-39 recovery phrase.
Later models, including the Mk4, Mk5 and Coldcard Q, were estimated to provide around 72 bits of entropy on vulnerable firmware, which CoinKite said is better but still below the expected security level.
With each additional bit of entropy, the time required to crack a seed increases exponentially. With modern hardware, a seed with 40 bits of entropy could potentially be cracked in a matter of hours. In contrast, cracking a seed with 128 bits of entropy (the standard for a 12-word seed phrase) would take billions of years, even if an attacker could harness all the computing power available on Earth.
Experts say the bug made it possible for attackers to recreate seed phrases and private keys without ever touching a user's hardware wallet. They believe the attackers generated huge numbers of possible wallet seeds ahead of time and then matched them to Bitcoin wallets on the blockchain.
The first large attack happened about 30 hours before Coldcard maker CoinKite publicly warned users about the problem. Galaxy Research said every transaction in the first attack looked almost identical, using the same transaction fee and leaving no change output.
This suggests the attacker already had the private keys and simply automated the theft.
CoinKite has released a firmware update to fix the bug. However, the company says installing the update does not make old recovery seeds safe. If a wallet was created using vulnerable firmware, users need to create a completely new recovery seed and move their bitcoin to the new wallet.

Coldcard issued new firmwares following the incident
The company also warned that simply restoring an old recovery phrase into another wallet will not solve the problem because the recovery seed itself is already weak. Users who protected their wallets with a strong BIP-39 passphrase are believed to face much lower risk because the passphrase adds another layer of security.
To make matters worse, some users have reported that the new firmware has effectively bricked certain models. One possible explanation is that it was rushed to release and has not yet undergone a thorough audit.
CoinKite also said wallets created using at least 50 dice rolls to generate the recovery seed are not affected by this bug. In its security advisory, the company strongly urged users to act quickly.
NVK, the founder of CoinKite, the parent company behind the wallets, issued a formal apology on X, saying that he and the team are “sorry, devastated, and heartbroken about the news.” He added that his team takes full accountability for the firmware bug, and is “working 24/7 to understand and fully scope the extent of the issue.”
Researchers believe more attacks could happen because the details of the vulnerability are now public.
The latest wave of thefts targeted many smaller wallets and used a different method to collect stolen bitcoin, making the activity harder to track. It is still unclear whether the same attacker changed tactics or if another attacker is now exploiting the same weakness.
Several well-known figures in the Bitcoin community have commented on the incident. Strike CEO Jack Mallers called it "one of the most serious wallet security incidents Bitcoin has seen."
Binance co-founder Changpeng Zhao also warned that "even hardware wallets can have bugs" and that "nothing is 100%", and said users should consider spreading their funds across multiple wallets to reduce risk.
Security experts say anyone who created a Coldcard wallet using affected firmware without extra protection should move their bitcoin immediately. The safest option is to generate a brand-new wallet with a new recovery seed on updated firmware or another trusted device and transfer all funds before attackers can access them.





