Coldcard Wallet Exploit Losses Top $100M as Firmware Flaw Traced to 2021

3 min read
Coldcard Wallet Exploit Losses Top $100M as Firmware Flaw Traced to 2021
PrimeXBT Editorial Team
Reviewed by PrimeXBT

Topics in article

Well over $100 million in Bitcoin has been drained through an ongoing exploit of Coldcard hardware wallets, with Galaxy Research tracing the losses to a firmware flaw dating back to March 2021. Market commentator Joe Consorti argues the attacker will struggle to spend much of the haul because every stolen coin remains visible on the public blockchain, while Coinkite is telling affected users that a firmware update alone will not protect them.

Well over $100 million worth of Bitcoin has now been stolen through the ongoing exploit of Coldcard hardware wallets, according to Galaxy Research. Yet market commentator Joe Consorti argues the thief may struggle to spend much of the haul, since every coin taken stays visible on the public blockchain.

Stolen coins stay traceable on-chain

Instead of dwelling on the size of the theft alone, Consorti pointed to an often-overlooked feature of Bitcoin: private keys can be compromised, but the movement of stolen coins remains visible to law enforcement, exchanges, and blockchain analysts. In a video accompanying his post, he argued the exploit was not a failure of the Bitcoin network itself but of wallet software that generated weak seed phrases on affected Coldcard firmware released after March 2021.

According to Consorti, Bitcoin "might be the worst money for crime ever invented." Galaxy Research also said about 90% of the stolen Bitcoin has not been moved. The firm has shared the confirmed attacker addresses with US law enforcement agencies, exchanges, and blockchain investigation firms.

A 2021 firmware flaw enabled the theft

The breach traces back to a build error in Coinkite's firmware version 4.0.1, released around March 2021, affecting primarily Coldcard Mk2 and Mk3 models. Those devices failed to use the hardware random-number generator correctly during seed creation, and fell back on a weaker software-based generator that slashed effective entropy to as low as 40 bits on older firmware, far below the intended 128 bits. Attackers pre-computed candidate seeds, matched them to on-chain addresses, and swept single-signature wallets without ever touching a physical device.

Its first major sweep hit around July 30, 2026, draining over 1,000 BTC from more than 1,200 addresses in under an hour, and two further waves followed. Galaxy Research has confirmed 1,596 BTC stolen across roughly 7,300 addresses in three confirmed attack waves. If suspected but unconfirmed activity is included, losses could reach 2,055 BTC, worth north of $130 million.

Coinkite tells owners a firmware update alone won't help

Coinkite has issued security advisories, released patched firmware for all affected models, and halted shipments of vulnerable inventory. However, the company stresses that updating firmware alone does not fix seeds already generated on vulnerable builds. Anyone who generated a seed on firmware around or before version 4.1.x must move funds to a wallet created with a freshly generated seed on clean, patched firmware, and Coinkite recommends using dice-roll entropy during setup for added independence from device-generated randomness.

Ripple CTO Emeritus David Schwartz compared the incident to historic failures in traditional finance, including MF Global in 2011, while noting that the insurance available to traditional brokerages does not currently extend to self-custody crypto losses. The Bitcoin protocol itself was not affected — this was a wallet-seed generation failure, not a network-level compromise.

Sources: CryptoPotato, CoinGape

Trading involves risk.

Most traded markets

XAU / USD
-0.9% 4,127.61
BRENT
+1.35% 73.620
BTC / USD
+0.7% 63,151.2
EUR / USD
-0.12% 1.14269
USTEC
-0.91% 29,428.7
XAU / USD.24
-0.9% 4,127.61
View all markets

Author

PrimeXBT
Our Editorial Team consists of leading experts with a proven record in the fields of trading, cryptocurrencies, blockchain and finance. We thoroughly research the sources of information in order to provide readers with quality content that serves edu...
Read author’s articles
Alert Triangle Risk Disclaimer
Disclaimer: Some past publications may be outdated. We recommend following our news to stay up to date with the latest information. For any questions, feel free to contact our support team via the chat below.
The content provided here is for informational purposes only. It is not intended as personal investment advice and does not constitute a solicitation or invitation to engage in any financial transactions, investments, or related activities. Past performance is not a reliable indicator of future results.
The financial products offered by the Company are complex and come with a high risk of losing money rapidly due to leverage. These products may not be suitable for all investors. Before engaging, you should consider whether you understand how these leveraged products work and whether you can afford the high risk of losing your money.
The Company does not accept clients from the Restricted Jurisdictions as indicated in our website/ T&C. Some services or products may not be available in your jurisdiction.
The applicable legal entity and its respective products and services depend on the client’s country of residence and the entity with which the client has established a contractual relationship during registration.

Today in markets

Browse Crypto News

Register Now

Trading involves risk

Get started in minutes

Our clients love how fast and simple our sign-up is. It takes just a few minutes to get started!

Get Started Get Started
Get started in minutes

Need Help?

Risk Warning:
Trading in leveraged products carries a high level of risk and may not be suitable for all investors.