A firmware flaw in Coinkite's Coldcard hardware wallets has reportedly let attackers drain more than 1,750 BTC — well over $100 million — from roughly 5,000 addresses since July 30. Coinkite has confirmed the underlying bug traces back to a March 2021 firmware error, though the running total comes from Galaxy Research's tracking of four separate attack waves. A patch is out, but recovering funds means migrating to a new address, and some users report devices bricking during the update.
A five-year-old firmware error in Coinkite's Coldcard hardware wallets has let attackers reconstruct Bitcoin private keys entirely offline, and the toll keeps climbing. Coinkite has confirmed the bug traces back to a March 2021 firmware error. Galaxy Research has estimated that the flaw has led to more than 1,750 BTC — well over $100 million — drained from roughly 5,000 addresses across multiple attack waves since July 30.
A build error rerouted seed generation
The 2021 build error meant Coldcard's firmware only checked whether a hardware random-number-generator flag existed, rather than whether it was actually enabled, silently routing seed generation through MicroPython's deterministic Yasmarang fallback instead of the true hardware RNG. As a result, effective entropy collapsed from a targeted 128 bits to roughly 40 bits on Mk2 and Mk3 devices, and about 72 bits on Mk4, Mk5 and Q devices — narrow enough for an attacker to brute-force candidate seeds offline and match them against public blockchain addresses.
Four waves of thefts since July 30
The first sweep hit July 30, draining 1,082 BTC from nearly 1,200 addresses in under an hour, according to Galaxy Research. A second and third wave followed through August 1, pushing the confirmed total to 1,367 BTC — about $89 million — from 4,585 addresses. A suspected fourth wave began August 2 and added roughly 449 more BTC from about 700 addresses, though Coinkite has not confirmed that figure.
A patch that carries its own risk
Coinkite shipped patched firmware for every model line within two days, but the update does nothing to repair a seed already generated under the flaw, so affected holders still have to migrate funds to a new address. Users and Casa co-founder Jameson Lopp have reported devices bricking during the update. Lopp is advising holders to move funds off a weak seed before touching the firmware at all.
The Bitcoin bridge Boltz temporarily disabled swaps, citing a sharp rise in AI-assisted probing that its small team couldn't keep pace with.
Source: Bankless
Trading involves risk.