0x131f0a07131f…131f0a04

ConfirmedSecurity687 vB147 sat/vB3 min decode

Hackers Drain 1,800 BTC From Coldcard Wallets in $116 Million Breach

An estimated 1,800 BTC (~$116 million) was drained from Coldcard wallets after a 2021 update cut seed entropy from 128 bits to as low as 40, per Galaxy Research.

Over $100 Million in Bitcoin Stolen From Investors in Coldcard Wallet Hack – Here’s What Went Wrong - MarketWise
WitnessOver $100 Million in Bitcoin Stolen From Investors in Coldcard Wallet Hack – Here’s What Went Wrong - MarketWiseAI-generated

Outputs

  1. An estimated 1,800 BTC worth roughly $116 million was drained from Coldcard wallets over the past week, per Galaxy Research.

  2. A 2021 software update reduced wallet entropy from 128 bits to as low as 40 bits; the flaw persisted for five years.

  3. Block's security team and anonymous researchers traced the bug; Coinkite confirmed the five-year scope on August 3.

  4. Users who generated seeds with their own randomness, such as physical dice, appear unaffected.

  5. Bitcoin fell ~$2,000 in three days after the first hacks on July 30; Fear and Greed Index hit 39 on August 6.

Hackers have drained an estimated 1,800 bitcoin (BTC), worth roughly $116 million, from Coldcard hardware wallets over the past week, according to data from Galaxy Research. The losses trace back to a software update in 2021 that quietly weakened the wallets' random-number generator, cutting effective seed security from 128 bits to as low as 40 bits and leaving the flaw undetected for five years.

Block, the financial-technology company trading under ticker XYZ, deployed its bitcoin engineering and security teams as the first reports of drained wallets surfaced. Working with independent researchers who have remained anonymous, the team dissected the firmware and traced the losses to the broken random-number generator used in wallet seed creation. Block disclosed the findings to Coldcard manufacturer Coinkite and published the full technical breakdown publicly within hours. Coinkite issued a preliminary advisory the same day and confirmed the five-year scope of the flaw on August 3.

How Did the Exploit Work?

Hardware wallets such as the bitcoin-only, air-gapped Coldcard generate a secret seed phrase whose security depends on randomness. A properly generated 128-bit seed is computationally infeasible to guess — the equivalent of a 38-digit PIN. The 2021 update reduced that entropy to roughly 40 bits, closer to a 13-digit PIN, which made brute-forcing users' private keys practical.

Auditors missed the regression. A paid outside security review also failed to catch it, even though Coldcard's code was public. The bug sat in plain view for five years before attackers began exploiting it.

The victim profile is unusual. These were not exchange users leaving coins in custodial accounts; they were self-custody holders who chose one of the market's most security-conscious devices. Wallet holders who supplied their own entropy when generating seeds — many using physical dice — appear to have avoided the vulnerability entirely.

Bitcoin's price fell roughly $2,000 in the three days after the first wave of hacks on July 30, though it has since recovered. The CoinMarketCap Crypto Fear and Greed Index stood at 39 out of 100 as of August 6.

What Are Holders Doing Now?

Bitcoin-tracking sites report coins flowing back onto exchanges at a pace not seen in years, as small holders re-evaluate their custody setups. The episode has revived debate over storage trade-offs:

  • ETFs such as BlackRock's iShares Bitcoin Fund (IBIT) eliminate key risk but introduce counterparty risk, market-hours-only trading and the loss of off-chain transferability.
  • Exchange and brokerage custody through Coinbase, Kraken, Gemini, Crypto.com or Fidelity Digital Assets offers institutional-grade security with the same counterparty exposure.
  • Dice-generated paper wallets provide the strongest user-controlled randomness but the weakest physical security.
  • Hardware wallets from other manufacturers, such as Ledger or Trezor, can be loaded with user-supplied randomness, and distributing keys across multiple vendors and locations limits single-point-of-failure losses.

Stephen Wooldridge II, an analyst for Stansberry Research's Crypto Capital newsletter, summarized the lesson: "Self-custody gives you full control over your funds, but good security practices are what let you keep them."

Why the Protocol Wasn't the Problem

The breach exposed a vendor build failure, not a Bitcoin protocol failure. The network processed valid transactions and signatures exactly as designed and settled them without appeal — immutability favors whoever holds the key. No consensus rule was broken; a firmware defect was.

The response cycle, however, differed sharply from traditional finance. Once coins started moving, independent researchers traced the root cause and published a complete technical post-mortem within a day, while the theft was still in progress. Closed-source bank breaches typically yield a press release and credit monitoring rather than a public autopsy.

The operational takeaway for the industry is already forming: wallet vendors face renewed pressure to prove entropy quality in firmware releases, and multisource key distribution is moving from best practice toward baseline expectation. Coinkite has confirmed the flaw's five-year scope, and affected holders must now decide whether to reseed on trusted hardware — a migration likely to dominate self-custody flows in the coming weeks.

via marketwise.com (Original)

More from Marcus Bennett

Marcus Bennett

Show full bio

Senior reporter covering business strategy at Mempool Brief.

413 articles