Coldcard Wallet Flaw Exposes $70 Million in Bitcoin, Shaking Self-Custody Faith

3D glossy Bitcoin coin with golden rim lighting against deep navy background, dramatic low-angle lighting, soft bokeh.

Firmware flaw leaves millions exposed

On July 30, a critical vulnerability in the Coldcard hardware wallet allowed attackers to steal over 1,000 bitcoin—valued at approximately $70 million—from unsuspecting users. The exploit targeted a flaw introduced in March 2021, when a firmware update weakened the randomness used to generate wallet recovery seeds on certain Coldcard models. Instead of using the device’s hardware-based random number generator, affected wallets relied on a software fallback seeded by predictable chip data, slashing the possible combinations to around four billion. This dramatic reduction made brute-force attacks feasible for determined adversaries.

Coinkite, the Canadian company behind Coldcard, acknowledged the bug after users reported missing funds and has since released emergency firmware updates. However, only new seeds generated on patched devices are secure; simply updating existing devices does not protect wallets created with compromised randomness. Coinkite CEO NVK urged users to immediately generate new seeds and migrate their bitcoin if their wallets were set up using vulnerable firmware versions.

Dormant wallets drained in minutes

The scale and speed of the attack stunned even seasoned observers. According to coindesk.com, Galaxy Research traced the theft to a 41-minute window between 01:10 and 01:51 UTC on July 30, during which 1,082.65 BTC was swept from 1,196 addresses across six blocks. Earlier reports had estimated losses at $38 million from about 500 wallets, but further analysis revealed the true toll was nearly double both in value and number of victims.


Of the 1,196 affected wallets, 1,183 used the native segwit address format introduced in 2017.

Many of the affected wallets had been dormant for years, holding coins untouched since as early as 2021. The attacker executed over 500 transactions within three consecutive blocks, consolidating large amounts of bitcoin into just four addresses that have yet to move any of the stolen funds. This rapid consolidation suggests careful planning and technical sophistication.

For some victims, their devices were powered off and stored far from internet access when the theft occurred.

BTCUSD : 24h trend

Weak randomness cracks Coldcard security

The root cause lay deep within Coldcard’s seed generation process. A build setting caused certain models—specifically Mk4, Q, and Mk5—to skip their hardware random number generator under specific circumstances. Instead, these devices fell back to a software method seeded by the chip’s serial number and internal clock registers. On paper this provided some unpredictability, but in practice it meant attackers could precompute all possible wallet seeds—about four billion combinations—and systematically attempt them until they gained access.

Every drained wallet was single-signature (meaning only one key was needed for spending) and most used modern native segwit address formats favored for their efficiency and lower fees. The bug can be traced back to a code change committed on March 1, 2021 and released as firmware version 4.0.0 that same month. While initial statements suggested only Mk3 models running version 4.0.1 or later were affected, subsequent analysis confirmed that newer models also harbored the vulnerability until emergency patches were issued.

Self-custody advocates face tough questions

The incident has sent shockwaves through the self-custody community—a group that prides itself on technical rigor and personal responsibility for private keys. Bitcoin commentator Guy Swann called it “the worst hit in bitcoin history to the most knowledgeable and ‘properly secured’ bitcoiners.” Lorenzo Valente of ARK Invest went further, arguing that such failures damage the reputation of hardware wallets and may push investors toward custodial solutions like ETFs despite their own risks.

Binance founder Changpeng Zhao (CZ) publicly urged crypto holders to diversify their storage by splitting funds across multiple wallets after news of the exploit broke. His advice reflects growing anxiety about relying too heavily on any single piece of hardware or software—even those marketed as “cold” or offline solutions.

Despite swift action from Coinkite—including public apologies and technical guidance—the fact remains that any wallet created with compromised firmware remains vulnerable until its funds are migrated elsewhere using a new seed generated with patched software.

It’s unclear how many users have successfully moved their assets since July 30 or whether additional attacks could follow if more dormant wallets remain unaddressed.

Developments to follow

If the 1,082.65 BTC stolen on July 30 from 1,196 Coldcard wallets—currently sitting in four addresses—begins to move or is sent to exchanges, it would immediately signal an attempt by the attacker to cash out or further obfuscate the funds; however, as of now, the bitcoin remains unmoved and any timeline for such activity remains unclear.