0x5607c18f5607…5607c192
Coldcard Flaw Drains $116 Million in Bitcoin Across Four Attack Waves
Attackers drained 1,816 BTC worth about $116 million from 5,200 Coldcard-linked addresses after a 2021 seed-generation flaw, Galaxy Research found.

Outputs
Attackers stole approximately 1,816 Bitcoin worth nearly $116 million from more than 5,200 Coldcard-linked addresses.
A 41-minute sweep on July 30 drained 1,196 addresses of roughly 1,083 BTC, about $70.2 million.
The vulnerability stems from a 2021 Coldcard software update that weakened recovery-phrase randomness, per Block's security team.
Coinkite advised all users who generated a seed on Coldcard devices to move funds immediately.
TRM Labs recorded 207 crypto incidents in the past six months totaling about $972 million in losses.
Attackers have drained approximately 1,816 Bitcoin, worth nearly $116 million, from more than 5,200 addresses tied to Coldcard hardware wallets, according to an on-chain analysis by blockchain intelligence firm Galaxy Research. The thefts unfolded in four waves starting Thursday and represent one of the largest hardware-wallet compromises on record.
The root cause sits in a 2021 Coldcard software update. According to a report by the Bitcoin engineering and security teams at financial technology firm Block, the update changed how the wallet generated its recovery phrase—the sequence of random words that regenerates the keys behind a Bitcoin address. The devices stopped using strong, unpredictable randomness and switched to a shortcut process that follows patterns.
That single design decision had severe operational consequences. Once attackers understood the pattern, they could replicate the generation process on their own computers, enumerate large numbers of candidate recovery phrases, and test which ones unlocked funded wallets. They never needed physical access to the device.
Who is exposed, and what is Coinkite doing?
Coldcard is built by Canadian firm Coinkite and marketed as offline "cold" storage for long-term Bitcoin holders—a segment that historically treated hardware wallets as the safest available custody option. The offline architecture was supposed to insulate keys from remote compromise; the seed-generation flaw bypassed that premise entirely.
Coinkite has issued an open letter strongly advising any user who generated a wallet seed on a Coldcard device to move their funds as soon as possible. The company acknowledged the severity in a social media post: "The last three days have been some of the hardest in this company's history, and for a lot of the people reading this, they've been something much worse."
Investigators have not attributed the attack to any specific actor. Recent large crypto thefts have frequently been linked to state-backed groups in North Korea or Russia, but no such connection has been established here.
How did the losses unfold?
Galaxy Research mapped the flow of funds tied to the vulnerability Block identified. The timeline shows industrial-scale, automated sweeps rather than opportunistic theft:
- July 30: In a 41-minute window, 1,196 addresses were fully drained of just over 1,083 Bitcoin, roughly $70.2 million.
- July 31: Follow-on reporting confirmed that about 594 Bitcoin, worth $38 million, was taken in a single 25-minute sweep of roughly 500 single-signature wallets.
- Friday midday to Saturday morning: A third wave drained 208 Bitcoin from 1,912 addresses.
- Monday morning: Investigators detected the fourth wave, bringing estimated total losses to 1,816 Bitcoin.
What does this mean for self-custody?
The breach has reignited a long-running debate among Bitcoin holders over custody models. Some users continue to argue for self-custody; others say the incident has pushed them toward large centralized platforms such as Binance and Coinbase.
Binance founder Changpeng Zhao weighed in on social media: "I'm a believer in self-custody, but it puts the burden on you." His comment underscores the market-structure question the hack raises—whether hardware-wallet vendors can retain institutional and retail trust when a firmware-level flaw can silently invalidate the security guarantee their products sell.
The incident also lands in a crowded enforcement and incident environment. Attackers launched 207 separate crypto incidents over the past six months, the most ever recorded in any half-year period by blockchain analytics platform TRM Labs. Total losses over that window reached about $972 million, less than half the $2.3 billion stolen in the first half of 2025.
Market impact, by contrast, stayed contained. Bitcoin and Ethereum each fell less than 1% since Thursday. The operational damage is concentrated in Coldcard's user base, which now faces an urgent migration window before attackers exhaust the remaining vulnerable seeds.
via fortune.com (Original)