BNB $593.42 +0.36%
XRP $1.08 -0.11%
ETH $1,872.64 +0.13%
BTC $64,132.36 +0.44%
BNB $593.42 +0.36%
XRP $1.08 -0.11%
ETH $1,872.64 +0.13%
BTC $64,132.36 +0.44%
BREAKING
Bitcoin News

15 Attackers Steal Over $130M in Bitcoin from 7,300 Coldcard Wallets

15 Attackers Steal Over $130M in Bitcoin from 7,300 Coldcard Wallets
15 Attackers Steal Over $130M in Bitcoin from 7,300 Coldcard Wallets

Community Trust ScoreVerified

89%
Real
Verified18 votes
Updated 5 hours ago

Fifteen attackers. Over $130 million gone. And the bleeding hasn’t stopped.

Galaxy Research confirmed that fifteen distinct bad actors are actively exploiting a firmware flaw inside Coldcard hardware wallets, draining Bitcoin from roughly 7,300 wallets so far. The vulnerability was discovered last week, but by the time any public advisory went out, the first attacks had already happened. Victims are scattered, many of them still unaware their funds are gone. As of Monday, Galaxy Research had received reports from 73 people. The most recent theft involved less than one Bitcoin — but when researchers pulled that thread, they found a broader pattern: 12 BTC stolen across 126 wallets, all tied to the same attacker.

Each wave of attacks gets its own identifier. The latest one carries the label footprint “O.”

Advertisement

Weak Entropy, Weak Keys

The root problem sits deep inside Coldcard’s firmware. Instead of routing seed generation through a true random number generator, the firmware used MicroPython’s pseudo-random number generator — a meaningful difference, and a catastrophic one. Per Coinkite, the manufacturer, the affected models are the Mk2 and Mk3. Those devices produced seed phrases with around 40 bits of entropy. The intended standard is 128 bits. That’s not a small gap. The Mk4 model does a bit better, coming in at roughly 72 bits of entropy, but it’s still vulnerable.

Lower entropy means weaker private keys. Weaker private keys mean an attacker with enough computational power can brute-force their way in. And because public keys are visible on the blockchain, attackers can scan for susceptible wallets without much friction. Basically, once the vulnerability became public knowledge, technically skilled individuals had a roadmap.

Coinkite co-founder Rodolfo Novak didn’t dodge responsibility. He took full ownership of the bug and issued an apology. Hotfixes have been pushed out for affected models. But Novak was direct about one hard limit: updating the firmware won’t fix seed phrases that were already generated by the faulty firmware. Those seeds are compromised. Full stop. Users sitting on wallets created with Mk2, Mk3, or Mk4 devices need to move their Bitcoin to a clean, unaffected wallet right now — not later.

90% of Stolen Bitcoin Hasn’t Moved

Here’s the strange part. Galaxy Research says 90% of the stolen Bitcoin is still sitting untouched. All coins from the first three waves of attacks haven’t moved at all. That’s a lot of money just parked on-chain, which is either a sign of attackers waiting for heat to die down, or something else entirely. Unclear yet. Law enforcement agencies globally are investigating, and victims are being urged to report losses to both local and federal authorities.

Hardware wallet security has always been sold on one core promise: your keys stay offline, and that keeps them safe. The Coldcard incident punches a hole in that promise, at least for older models. The flaw didn’t require physical access. It didn’t require social engineering. It required knowing that a firmware decision made years ago produced keys that were never as strong as users believed.

That’s a hard thing to sit with.

Coinkite has been clear that hotfixes exist, but equally clear that hotfixes can’t undo the past. Any seed phrase generated under the faulty firmware is still a weak seed phrase, patched device or not. The only real fix is moving funds. And for users who haven’t kept close tabs on their wallets — maybe they set it up years ago and didn’t think much about it since — there’s a real chance they won’t know they’re at risk until it’s too late.

The fifteen attackers aren’t operating identically. Each has its own footprint, its own pattern, its own catalog of targeted wallets. Researchers have been tracking them separately. The most recent attacker was only identified because one user flagged a small theft, less than one Bitcoin, which sounds almost trivial until you realize it cracked open a much bigger picture across 126 wallets.

Galaxy Research keeps receiving new reports. The 73 victims confirmed as of Monday probably won’t be the final count.

Coinkite’s advisory is out, the hotfixes are distributed, and law enforcement is involved. But the stolen funds — most of them, anyway — are still sitting right there on the blockchain, unspent, watching.

Frequently Asked Questions

Which Coldcard wallet models are affected by the firmware flaw?

The Mk2 and Mk3 models are the most severely affected, producing seed phrases with around 40 bits of entropy. The Mk4 model is also vulnerable, generating roughly 72 bits of entropy instead of the intended 128 bits.

Will updating Coldcard firmware protect stolen or at-risk Bitcoin?

No. Coinkite co-founder Rodolfo Novak said hotfixes have been distributed, but updating firmware does not fix seed phrases already generated by the faulty firmware. Affected users must move their Bitcoin to a new, unaffected wallet.

Community Trust IndexModerate Confidence
89%
Real
Real89%11%Fake
18 community signals

Evie Vavasseur

Evie Vavasseur is a crypto writer and digital content specialist covering the latest developments in blockchain technology, decentralized finance, and the broader digital asset ecosystem. With a keen eye for emerging trends, Evie provides accessible and insightful coverage of cryptocurrency markets, NFTs, and Web3 innovations for The Currency Analytics.

Advertisement

Related Stories