A Five-Year-Old Firmware Flaw Has Drained $130 Million From Coldcard Bitcoin Wallets
A 2021 build error in Coldcard's firmware left Bitcoin seed generation predictable. Attackers have now drained roughly $130 million from affected wallets.
Hackers have stolen roughly $130 million in Bitcoin from Coldcard hardware wallets since July 30, exploiting a firmware bug that Coinkite, the device’s Canadian manufacturer, traces back to a build released in March 2021. Alex Thorn, Galaxy Digital’s head of firmwide research, said on Tuesday that Galaxy Research now counts at least 15 separate attackers exploiting the flaw independently, up from the handful of coordinated operators behind the first waves of theft, according to Crypto Times. TechCrunch reported that Tom Robinson, co-founder and chief scientist of crypto-monitoring firm Elliptic, confirmed the roughly $130 million estimate as accurate.
Table Of Content
The bug is significant because a Coldcard is meant to be “cold” storage: a device that generates and holds the private keys controlling a user’s Bitcoin entirely offline, specifically so malware, phishing, or a compromised computer can never reach them. Coinkite’s own security advisory confirms the flaw let attackers reconstruct those supposedly unreachable keys without ever touching a victim’s device.
How a Five-Year-Old Build Error Broke “Cold” Storage
A technical analysis from Block, reported by The Hacker News, traced the root cause to a March 2021 firmware integration error. Coldcard’s production build sets a flag called MICROPY_HW_ENABLE_RNG to zero because Coinkite supplies its own hardware random-number generator wrapper. A library the firmware depends on, libngu, checked only whether that flag existed rather than whether it was turned on, binding the affected builds to MicroPython’s Yasmarang fallback generator instead of the device’s STM32 hardware random-number generator. The fallback seeded itself once, from the chip’s unique ID and timer registers at startup, and collected no further randomness afterward, leaving a predictable state that an attacker can work backward from without physical access to the device.
Coinkite’s advisory says the practical effect was seeds generated with far less randomness than intended: about 72 bits of entropy on the Mk4, Mk5, and Q models instead of the 128 bits a standard 12-word BIP-39 seed should carry, and, per Coinkite’s own estimate as relayed by The Hacker News, roughly 40 bits on the earlier Mk3. An attacker who can narrow down a device’s unique ID, its boot timing, and the sequence of prior random-number calls can regenerate candidate seeds offline, then check each candidate’s derived address against the public blockchain until one matches a funded wallet. Three other Coinkite products, TAPSIGNER, OPENDIME, and SATSCARD, run on different code and are not affected.
From a 41-Minute Sweep to a 15-Attacker Free-for-All
Galaxy Research first tied the exploit to a single sweep on July 30, when one attacker drained 1,196 Bitcoin addresses in 41 minutes, taking about 1,082.65 BTC, worth roughly $70.2 million at the time, The Hacker News reported. Two further waves over the following days pushed Galaxy’s observed total to about 1,367 BTC, or $88.6 million, across 4,585 addresses. By this week, Thorn said the picture had changed again: rather than a small number of coordinated operators, Galaxy now sees “numerous different attackers” working through whatever vulnerable wallets remain, a mix of the original operators and newer imitators now that the technique is public and well understood.
Crypto Times reported that Galaxy’s confirmed, victim-corroborated total has since climbed to 1,596 BTC (over $100 million) across roughly 7,300 addresses, spanning three confirmed waves plus 14 smaller incidents. Adding a fourth wave that Galaxy holds with “medium-high confidence” but has not yet confirmed through victim reports lifts the suspected total to about 2,055 BTC, or $130 million, across more than 7,700 addresses. Thorn said the stolen coins had sat untouched for an average of about 3.18 years before being swept, meaning most victims were long-term holders who believed their coins were safely in cold storage. Jonathan Goodman, who told TechCrunch he lost $1.6 million from his own Coldcard, described his precautions on X: “I never shared my seed phrase with anybody. My devices never touched the internet. Everything was kept in multiple safes and safety deposit boxes.” None of it mattered, he wrote, because the weakness was already sitting in a single line of firmware code from 2021.
Coinkite’s Fix, and Why Updating Alone Will Not Save an Old Seed
Coinkite published its advisory on July 30 and had corrected firmware ready for every affected model and release track by July 31: version 4.2.0 for the Mk2 and Mk3, 5.6.0 for the standard Mk4 and Mk5, 1.5.0Q for the standard Q, and separate 6.6.0X and 6.6.0QX builds for their Edge release tracks. The fix only changes how new seeds are generated from now on. Installing it does not repair a seed a device already generated on vulnerable firmware, so Coinkite is telling affected owners to update the firmware first, then generate an entirely new seed and move their coins to it, rather than continuing to trust the old one.
The advisory carves out two exceptions. A seed created with at least 50 independent, private dice rolls entered through Coldcard’s “Add Dice Rolls” option was not weakened by the bug, since that entropy came from the dice rather than the flawed generator. A strong, unique BIP-39 passphrase, a separate secret layered on top of the seed words, also adds a barrier an attacker must still break even against a predictable seed, though Coinkite still recommends migrating to a freshly generated seed regardless of passphrase strength.
What Coldcard Owners Should Do Now
Coinkite’s guidance comes down to three steps. First, check which firmware version originally generated your current seed, not just which version is installed today, since updating alone does not retroactively fix a seed that already exists. Second, install the fixed firmware for your exact model and release track, standard or Edge, from Coinkite’s official download page. Third, unless your seed was created from at least 50 private dice rolls or is protected by a strong, unique BIP-39 passphrase you trust, generate a brand-new seed on the updated firmware and move your funds to it before treating the old seed as retired.
The Coldcard incident lands in a rough year for crypto security generally. TechCrunch cited blockchain-monitoring firm TRM Labs’ count of more than 200 hacks against cryptocurrency companies so far in 2026, with total losses topping $950 million. What sets this one apart is that it undercuts the core premise of cold storage itself: that keeping a device offline is enough to keep its keys safe. Here, the theft never required an attacker to reach the victim’s hardware at all, only to reconstruct what a flawed line of code had already made guessable.








No Comment! Be the first one.