BNB $589.65 +0.21%
XRP $1.07 -1.26%
ETH $1,867.82 -1.92%
BTC $63,007.98 -2.10%
BNB $589.65 +0.21%
XRP $1.07 -1.26%
ETH $1,867.82 -1.92%
BTC $63,007.98 -2.10%
BREAKING
Bitcoin News

Coldcard Firmware Bug Drained Bitcoin Wallets Worth Nearly $70 Million

Coldcard Firmware Bug Drained Bitcoin Wallets Worth Nearly $70 Million
Coldcard Firmware Bug Drained Bitcoin Wallets Worth Nearly $70 Million

Community Trust ScoreVerified

90%
Real
Verified10 votes
Updated 2 hours ago

What happened

An attacker cracked it. Weak seed generation baked into certain Coldcard hardware wallet firmware let someone drain bitcoin from a large number of accounts — tens of millions of dollars gone, probably more than most users imagined possible from a device marketed as one of the most secure cold storage options on the market.

The flaw wasn’t some exotic zero-day. It traced back to a software-library migration in 2021 that quietly defaulted to a weaker randomness generator during wallet seed creation. Seed generation is basically the whole ballgame for hardware wallets — if the entropy is predictable, the wallet is predictable. And if the wallet is predictable, a patient attacker with the right tools can work backward, reconstruct seeds, and empty accounts one by one. That’s apparently what happened here. The attacker used automated processes to drain compromised wallets fast, paid elevated transaction fees to push transactions through before anyone noticed, and moved funds with a level of operational discipline that suggests this wasn’t improvised. Someone planned it carefully and understood exactly how blockchain transparency works — and how to outrun it.

Nearly $70 million in bitcoin. Gone.

Advertisement

The historical context

It’s not the first time a security assumption turned out to be wrong in a very expensive way. Mt. Gox collapsed in 2014 after security failures led to the loss of 850,000 bitcoin. The DAO hack in 2016 burned through millions in investor funds by exploiting a flaw in smart contract code that developers hadn’t caught. Each of those events felt, at the time, like a turning point — a moment when the industry would finally get serious about security. And each time, the industry did shift, at least somewhat. Audits got more common. Practices improved. But the gap between how secure people believed their tools were and how secure those tools actually were never fully closed.

The Coldcard situation fits that pattern uncomfortably well. Users did what they were supposed to do. They bought a reputable hardware wallet. They generated seeds offline, away from internet-connected devices. They followed the standard playbook. And it still wasn’t enough — because the vulnerability wasn’t in their behavior. It was in the firmware they trusted.

That’s the part that stings.

Why it matters

For Coinkite, the company behind Coldcard, the technical problem is probably the easier half of what they’re dealing with. Patching firmware is hard, but it’s solvable. Rebuilding trust in a market where trust is basically the entire product — that’s a different kind of hard. Hardware wallets exist because people don’t trust software wallets, exchanges, or custodians. The pitch is simple: your keys, your coins, offline, safe. When that pitch breaks down, the damage isn’t just financial. It’s reputational in a way that’s difficult to walk back.

There’s also the communication problem. Coinkite’s policy purges customer records after 120 days. The privacy rationale makes sense — fewer records means fewer data points for an attacker or a subpoena to grab. But it also means the company can’t easily identify and directly contact users who may have generated seeds on affected firmware versions. So warnings had to travel through community channels, industry peers, and social media rather than direct outreach. That gap between manufacturer and user base, in a moment of crisis, is a real structural weakness.

And for users who didn’t know any of this was happening — they’re now tasked with verifying whether their wallet was affected and migrating to new wallets carefully, without making mistakes that could expose funds during the transition. Not a simple task for many people.

The users who came through unscathed, per available information, were largely those who added independent entropy — dice rolls, for instance — or used strong BIP-39 passphrases on top of the device-generated seed. Those extra layers weren’t standard practice for most people. They probably should be now.

What to watch

A few things worth tracking as this plays out.

Adoption of Coldcard’s new firmware updates matters. A fast, widespread uptake would at least show that the existing user base is engaged and taking steps to address the exposure. Slow adoption would be a different kind of signal.

Third-party audit frequency across the hardware wallet sector is worth watching too. If competitors start commissioning more aggressive independent reviews — not just internal checks — it’d suggest the industry is taking the lesson seriously rather than waiting for the next incident.

Movement of the identified stolen bitcoin addresses is probably the most operationally useful thing to track right now. Blockchain transparency cuts both ways. The attacker used it to move fast; researchers and exchanges can use it to monitor where those funds go. Recovery is unlikely, but not impossible if the attacker makes a mistake trying to cash out.

One more angle that Coinkite itself has raised: the possibility that AI tools were used to find the flaw in their open-source firmware. No concrete evidence supports that theory, and Coinkite hasn’t gone further than speculation. But it’s worth sitting with. If automated AI-driven code scanning can identify subtle entropy weaknesses faster than traditional security reviews, that changes the threat model for every open-source wallet project. It’d mean that publishing code openly — which is generally considered a security positive, because the community can review it — might simultaneously hand attackers a searchable target. The implication for hardware wallet manufacturers is that AI-assisted security audits may stop being optional and start being necessary.

No details yet on whether law enforcement is involved or whether any exchange cooperation has been requested to flag the stolen addresses. Unclear if any of the affected users have organized any kind of legal response against Coinkite.

What’s clear: the 2021 library migration introduced a flaw that took years to weaponize and seconds to exploit at scale. Elevated fees, automated draining, careful timing — whoever did this knew exactly what they were doing, and they’d been waiting for the right moment.

Community Trust IndexModerate Confidence
90%
Real
Real90%10%Fake
10 community signals

Sakamoto Nashi

Nashi Sakamoto is a dedicated crypto journalist from the Virgin Islands who brings expert analysis on Bitcoin, Ethereum, DeFi protocols, and the broader digital asset ecosystem to The Currency Analytics.

Advertisement

Related Stories