What to Know
- An attacker stole roughly 594 bitcoin, worth about $38 million, from around 500 single-signature wallets linked to a Coldcard hardware wallet key-generation flaw.
- The sweep took place between 01:31 and 01:56 UTC on Friday, moving funds across 500 transactions within a three-block window.
- The vulnerability was introduced in Coldcard firmware 4.0.0 in March 2021 and affected how some wallet seeds were generated.
- The flaw caused devices to skip their hardware randomness generator and fall back to predictable software-based key generation seeded by nonsecret chip data.
- Coinkite warned users who generated a seed on an Mk3 running firmware 4.0.1 or later, while saying Mk4, Q and Mk5 appear unaffected based on early analysis.
- Every drained wallet was single-signature, each held more than 0.15 BTC, and many had been dormant for years.
- The stolen coins spanned 2021 to 2026, closely matching the apparent age of the flaw.
- Bitcoin traded above $64,000 in early Asian hours, with the drain showing little visible impact on the broader market price.
Coldcard Bitcoin Wallets Hit by Randomness Failure
A major bitcoin wallet security incident has exposed how a failure in randomness generation can turn supposedly unreachable private keys into targets. Roughly 594 bitcoin, valued at about $38 million, was drained from around 500 separate single-signature wallets after an attacker exploited a flaw in the way certain Coldcard hardware wallets generated wallet seeds.
The theft unfolded quickly. Funds were swept between 01:31 and 01:56 UTC on Friday, moving through 500 transactions inside a three-block window. The attack involved 1,324 chunks of bitcoin, and 562 BTC was later consolidated into a single address that has not moved. The speed, scale and structure of the sweep suggest a highly organized operation focused on wallets that shared a specific key-generation weakness rather than a broad compromise of the bitcoin network itself.
Coldcard is a bitcoin hardware wallet made by Canadian firm Coinkite. The device is designed to store private keys offline, away from internet-connected computers that may be exposed to malware, phishing or remote intrusion. Its product line includes Mk2, Mk3, Mk4, Q and Mk5 generations, with different models released over several years. In this incident, the exposure centers on the firmware running when a wallet was first created, not simply the model purchased or the current firmware installed.
How Predictable Seeds Created the Opening
A bitcoin wallet seed is meant to be secret and random. In normal use, that seed phrase controls access to the funds associated with a wallet, and it is supposed to be drawn from a search space so large that guessing it is functionally hopeless. That security assumption depends on strong randomness. If the randomness collapses, the seed can become far easier to reproduce, narrow down or attack.
The flaw tied to the Coldcard incident was introduced in firmware 4.0.0 in March 2021. A build setting caused affected devices to skip their hardware randomness generator. A check in a supporting library looked only for whether that setting existed, rather than verifying whether it was switched on. As a result, key generation quietly fell through to a basic software substitute.
That substitute was seeded using nonsecret chip data, including the chip serial number and clock registers. Those values are not designed to be private. A serial number is fixed factory metadata, while clock values are timing-related state that an attacker may be able to narrow down or measure using a device of their own. In practical terms, the affected wallets did not benefit from the level of entropy users would expect from a hardware wallet seed-generation process.
The change has been traced to a commit dated March 1, 2021, and shipped in firmware 4.0.0 that month. Coinkite has warned users who generated a seed on an Mk3 running version 4.0.1 or later. The company has also said that Mk4, Q and Mk5 are not affected based on early analysis. Both the warnings and the technical review remain preliminary, leaving room for further clarification as investigators and wallet makers continue to examine the incident.
Why the Timing of Seed Creation Matters
One of the most important details for Coldcard users is that exposure depends on the firmware present at the moment the seed was first created. A hardware wallet bought at one point, updated later and then used for years may not be judged solely by its current firmware version. The key question is which software version generated the original seed phrase that controls the funds.
This distinction matters because a seed, once generated, usually remains the root secret for a wallet until the user creates a new wallet and moves funds. Updating firmware after a weak seed has already been created does not automatically make that existing seed stronger. If the seed was derived from predictable or insufficiently random inputs, the associated addresses may remain exposed even if the device later runs patched or newer firmware.
The wallets drained in the attack had several common traits. Every drained wallet was single-signature, and each held more than 0.15 BTC. Many had been dormant for years, a pattern that may indicate the attacker searched for wallets created during the vulnerable period and then swept those with meaningful balances. The coins spanned 2021 to 2026, matching the apparent age of the flaw almost exactly.
The incident also highlights the different risk profile of single-signature storage. In a single-signature wallet, one valid private key is enough to spend the funds. Multisignature setups can add additional checks by requiring more than one key to authorize a transaction, but they also introduce extra operational complexity. The Coldcard theft shows that key-generation quality is foundational: if the root seed is weak, the security of the wallet can be compromised even if the device is normally kept offline.
Exposure Extends Beyond Standard Wallet Seeds
The vulnerability was not limited to ordinary wallet seed creation. The same generator was used in several Coldcard features, including paper wallet private keys, seed-splitting masks, device cloning keys and Key Teleport transfers. That broader footprint makes the issue more significant because it reaches beyond a single wallet workflow.
Paper wallets are especially sensitive in this context because the generated output can become the private key directly, with no further derivation step to add protective structure. If that output was derived from predictable data, the resulting private key may be exposed in a more direct way. Seed-splitting masks and device cloning keys also depend on the assumption that generated values are unpredictable, which means weakness in the generator could affect how users backed up, transferred or protected wallet material.
For affected users, the critical practical lesson is that randomness is not an abstract technical detail. It is the root of wallet security. Hardware wallets are trusted because they aim to isolate key material and generate secrets securely, but their security depends on correct implementation at the firmware and library level. A small configuration or validation error can undermine the assumptions that make long-term self-custody viable.
Market Reaction Remains Muted Despite Large Theft
Bitcoin traded above $64,000 in early Asian hours, with the widely observed drain appearing to have little visible impact on the market price. That muted reaction reflects the distinction between a wallet-specific security failure and a protocol-level failure. The bitcoin network itself was not described as compromised; rather, the issue centered on how certain wallet software generated secrets.
Still, the theft is significant for the self-custody ecosystem. Hardware wallets are widely used by long-term holders because they reduce exposure to online threats. When a vulnerability affects seed generation, it strikes at the most sensitive layer of self-custody. Market participants may therefore treat the event as a security and operational risk issue rather than a direct monetary policy, liquidity or network-consensus concern.
The consolidation of 562 BTC into a single address that has not moved may remain a focus for blockchain watchers. However, the funds being visible on-chain does not guarantee recovery. Bitcoin transactions are final once confirmed, and tracing coins is different from reclaiming them. Investigators, wallet makers and affected users may continue monitoring the destination address and any subsequent movement.
What Coldcard Users Are Watching Now
Coinkite has warned users who created seeds on Mk3 devices running firmware 4.0.1 or later, while saying Mk4, Q and Mk5 appear unaffected so far based on early analysis. The emphasis on early analysis is important. Security investigations can evolve as teams reproduce conditions, review code paths and test whether related features are also exposed.
Users trying to assess their risk will likely focus on three questions: which Coldcard model they used, which firmware generated the seed, and whether the wallet was single-signature. The incident also reinforces the importance of maintaining accurate records about wallet setup dates, firmware versions and backup procedures. Without those records, determining exposure can become more difficult.
Technical traders and broader market participants may continue watching whether the attacker moves the consolidated bitcoin and whether any additional sweeps occur. A lack of immediate price impact does not reduce the seriousness of the theft for affected holders. The event is a reminder that custody risk can be separate from market risk: an investor can correctly assess bitcoin’s market direction and still face losses if private-key security fails.
For the hardware wallet industry, the Coldcard incident is likely to sharpen scrutiny of randomness, firmware release practices and independent review. The core promise of offline storage is only as strong as the procedures used to create and protect keys. In bitcoin self-custody, the seed is the asset’s ultimate control point, and any weakness at that moment of creation can remain hidden for years before being exploited in minutes.
Frequently Asked Questions (FAQs)
What happened in the Coldcard bitcoin wallet incident?
An attacker exploited a flaw in how some Coldcard hardware wallets generated keys, draining roughly 594 bitcoin worth about $38 million from around 500 single-signature wallets.
How fast did the bitcoin theft happen?
The sweep took place between 01:31 and 01:56 UTC on Friday. Funds moved through 500 transactions inside a three-block window, making the attack both rapid and highly coordinated.
Which Coldcard firmware introduced the flaw?
The vulnerability was introduced in Coldcard firmware 4.0.0 in March 2021. Coinkite has warned users who generated a seed on an Mk3 running firmware 4.0.1 or later.
What made the affected wallet seeds vulnerable?
Affected devices skipped the hardware randomness generator and fell back to software-based key generation seeded with nonsecret chip data, including the serial number and clock registers.
Are all Coldcard devices affected?
Coinkite has said Mk4, Q and Mk5 are not affected based on early analysis. The warning specifically focuses on users who generated seeds on Mk3 devices running firmware 4.0.1 or later.
Why does the firmware version at seed creation matter?
The seed is the root secret controlling the wallet. If it was generated while vulnerable firmware was running, later updates may not change the underlying weakness of that existing seed.
Did the incident affect bitcoin’s market price?
Bitcoin traded above $64,000 in early Asian hours, and the wallet drain appeared to have little visible impact on the broader market price.
What types of wallets were drained?
Every drained wallet was single-signature and held more than 0.15 BTC. Many had been dormant for years, and the affected coins spanned 2021 to 2026.
Why is randomness so important for hardware wallets?
Randomness is what makes a wallet seed practically impossible to guess. If the seed-generation process becomes predictable, attackers may be able to identify and drain wallets that should have been secure.
Photo by https://kaboompics.com/ on Pexels
