Nearly $89M in Bitcoin Allegedly Drained After Coldcard Firmware Vulnerability
MANILA, Philippines — Nearly $89 million worth of Bitcoin was allegedly drained from thousands of Coldcard hardware wallet addresses after attackers exploited a firmware vulnerability that weakened the randomness used to generate wallet recovery phrases, according to on-chain analysis and security advisories released in late July and early August.
The incident has been linked to a flaw in firmware released in 2021 that affected the way certain Coldcard devices generated wallet recovery seeds. Researchers say attackers were able to reconstruct vulnerable private keys offline, identify matching wallet addresses on the Bitcoin blockchain, and transfer funds without needing physical access to the hardware wallets.
Blockchain analysis by Galaxy Research identified approximately 1,367.05 BTC—worth about $89 million at recent prices—as having been drained from 4,585 wallet addresses in multiple coordinated sweeps beginning in late July. The largest wave occurred on July 30, when more than 1,082 BTC was moved from nearly 1,200 addresses in less than an hour.
According to hardware wallet maker Coinkite, the vulnerability stemmed from a firmware change introduced in March 2021 that inadvertently caused affected devices to generate wallet recovery seeds using a deterministic software pseudorandom number generator instead of the intended hardware-based true random number generator. The resulting reduction in entropy made some recovery phrases significantly easier to brute-force than expected.
The company said updating affected devices to the latest firmware does not secure wallets whose recovery seeds were originally generated using the vulnerable versions. Instead, users are advised to install the patched firmware, generate an entirely new wallet seed, verify their backups, and transfer any remaining funds to the new wallet.
Coinkite has identified several affected firmware versions across its Coldcard Mk2, Mk3, Mk4, Mk5, and Q hardware wallets. Devices protected with sufficient user-generated entropy—such as at least 50 independent dice rolls—or a strong, unique BIP-39 passphrase are believed to have been significantly more resistant to the attacks, though the company still recommends migrating funds as a precaution.
The incident has renewed debate over self-custody security within the Bitcoin community. Coldcard wallets have long been regarded as among the industry’s most secure air-gapped hardware wallets, and the breach is being viewed as one of the largest publicly documented losses linked to a firmware-based entropy failure rather than phishing, malware, or supply-chain compromise.
Researchers caution that the estimated losses are based primarily on Galaxy Research’s on-chain pattern analysis and that not every affected address has been conclusively proven to originate from the firmware flaw. It also remains unclear whether all of the observed thefts were carried out by the same attacker or group.
Coinkite has since released emergency firmware updates and published a technical explanation of the vulnerability, while warning that additional attacks against wallets created with vulnerable firmware may still be possible if users have not yet migrated their funds.




