BNB $586.18 +0.78%
XRP $1.06 -1.39%
ETH $1,840.25 -0.88%
BTC $62,561.65 -0.92%
BNB $586.18 +0.78%
XRP $1.06 -1.39%
ETH $1,840.25 -0.88%
BTC $62,561.65 -0.92%
BREAKING
Bitcoin News

Coldcard Firmware Flaw Drains 1,367 Bitcoin Across 4,585 Wallets

Coldcard Firmware Flaw Drains 1,367 Bitcoin Across 4,585 Wallets
Coldcard Firmware Flaw Drains 1,367 Bitcoin Across 4,585 Wallets

Community Trust ScoreVerified

86%
Real
Verified21 votes
Updated 25 seconds ago

A trusted name in Bitcoin security just took a serious hit. Coldcard, the hardware wallet brand widely favored by self-custody advocates, is at the center of a breach that has drained roughly 1,367 BTC — worth around $88.6 million — and could push total losses to $114 million before it’s over.

The root cause goes back further than most people realize. A firmware update shipped in March 2021 quietly introduced a weak software fallback for generating wallet seeds. That flaw cut the security of private keys on the Mk3 model from 128 bits down to about 40 bits. Forty bits. That’s not a minor degradation — it’s the kind of reduction that makes keys guessable through brute force. And because the vulnerability lived inside the seed generation process itself, wallets that had never once touched the internet were still exposed. One Canadian user found that out the hard way: 18.25 BTC gone from a wallet sitting in a safety deposit box, despite following every recommended security guideline. That detail is worth sitting with. Air-gapped. In a bank vault. Still drained.

Not a one-time hit.

Advertisement

Galaxy Research has tracked three distinct attack waves so far. They’ve flagged roughly 600 suspect addresses to federal investigators and warned that a fourth wave is probably coming. The theft started at an estimated $38 million, then surged over the weekend as more wallets got hit across 4,585 addresses. Galaxy’s own Alex Thorn said the systematic nature of the thefts seems to point toward a large language model being used to identify the flaw in Coldcard’s open-source firmware. That’s a striking claim — basically, AI found the hole the developers missed.

Coinkite’s AI Review Missed What Attackers Found

Coinkite, the company that makes Coldcard, ran an AI-based review of its own firmware and didn’t catch the vulnerability. The attackers apparently did. It’s a painful irony: the same kind of technology Coinkite used defensively seems to have been turned against them offensively. The firmware is open-source, which has always been part of Coldcard’s pitch — transparency, community scrutiny, no black boxes. But open-source cuts both ways. Anyone can read the code, including people looking for something to exploit.

Coinkite hasn’t hidden from the problem. The company acknowledged the breach and the failure of its own AI review. No spin, at least publicly. But acknowledgment doesn’t move the stolen Bitcoin back.

Galaxy has been clear that all vulnerable Coldcard devices remain at risk of being fully drained. They’re still tracking the flow of stolen funds and working with federal investigators. Some of the more recent attacks might be stoppable by preemptively settling transactions in the mempool — essentially front-running the attacker — but that’s a messy fix and carries its own complications. It’s not really a solution so much as damage control.

Self-Custody’s Foundational Promise Under Pressure

Hardware wallets exist for one reason: to keep your Bitcoin safe without trusting a third party. That’s the whole pitch. Not your keys, not your coins — and Coldcard built its reputation on being the serious option for people who took that principle seriously. The Mk3 was marketed at the paranoid, the careful, the technically sophisticated. And yet here we are.

The breach doesn’t just hurt Coldcard’s brand. It rattles something more fundamental. If a wallet that never connected to the internet can be drained because of a firmware flaw introduced five years ago, the self-custody model has a problem that better hardware alone won’t fix. Software matters. Seed generation matters. And apparently, so does whoever is auditing your code — and how.

The crypto industry has spent years arguing that self-custody is safer than leaving funds on exchanges. That argument isn’t wrong, but it’s clearly more complicated than it used to sound. Exchanges get hacked. Hardware wallets, it turns out, can carry silent vulnerabilities for years before anyone notices. Neither option is clean.

There’s also a broader question here about AI’s role in security — on both sides of the fight. Defenders are using it to audit code. Attackers are apparently using it to find what defenders missed. That dynamic isn’t going away. If anything, it’s going to get faster and harder to manage as the tools improve. The Coldcard situation is probably an early example of something the industry will see more of, not less.

For now, Galaxy Research is pushing affected users to move funds immediately if they haven’t already. The fourth wave they’re warning about hasn’t hit yet — or at least hadn’t as of the latest update. But with 4,585 addresses already compromised and federal investigators still piecing together the full picture, the window to act is narrow.

Galaxy has provided approximately 600 suspect addresses to federal investigators.

Frequently Asked Questions

What caused the Coldcard hardware wallet vulnerability?

A March 2021 firmware update introduced a weak software fallback for generating wallet seeds, reducing private key security on the Mk3 model from 128 bits to roughly 40 bits, making keys guessable without physical access to the device.

How much Bitcoin has been stolen in the Coldcard breach?

Galaxy Research reports approximately 1,367 BTC stolen — worth around $88.6 million — spread across 4,585 addresses, with potential total losses nearing $114 million if a fourth attack wave materializes.

Did Coinkite know about the flaw before the attacks?

No. Coinkite ran its own AI-based review of the firmware and failed to detect the vulnerability that attackers later exploited, per the company’s own acknowledgment.

Community Trust IndexHigh Confidence
86%
Real
Real86%14%Fake
21 community signals

Pankaj K

Pankaj is a skilled engineer with a passion for cryptocurrencies and blockchain technology. He brings a technical perspective to his coverage of smart contracts, layer-2 solutions, and crypto infrastructure.

Advertisement

Related Stories