
Coldcard Mk3 firmware bug since 2021 let attackers drain 1,082 BTC from 1,200 wallets. CZ: split funds. Coinkite patch doesn't fix compromised seeds.
A firmware bug in Coldcard Mk3 devices drained roughly 1,082 BTC from nearly 1,200 wallets in a 41-minute window early July 30. Galaxy Research later revised the tally to about 594 BTC across roughly 500 addresses, saying some initial figures captured transactions not tied to the exploit.
The vulnerability lived in the random number generation used to build recovery seeds. Seeds created with affected firmware builds, dating back to March 2021, were not truly random. That made them guessable by attackers.
The exploit ran from 1:10 to 1:51 AM UTC. The attackers targeted addresses that had been inactive for long periods, suggesting they identified vulnerable seeds in advance. The compromised firmware builds meant wallets created during that period were vulnerable for more than five years.
Coinkite, the Toronto-based maker of Coldcard, released a patched firmware version 4.2.0 and above. The company said updating firmware alone does not fix the problem. Users who created wallets with compromised seeds must generate new seeds on patched hardware and move their funds to new addresses. The newer Mk4, Q, and Mk5 models were not affected.
Changpeng Zhao, the Binance founder, advised users to split their funds across multiple wallets. He also noted the trade-off: more wallets mean more seed phrases to manage and more room for error.
For retail holders who set up Mk3 devices during the 2021 bull run and have not touched them since, the first step is checking which firmware version their device ran at wallet creation. Coinkite's advisory lists the affected build range. If the wallet falls in that window, moving funds to a fresh address on patched hardware is urgent.
The 1,082 BTC haul, worth roughly $70 million at the time of the attack, is one of the largest hardware wallet exploits on record. The attackers specifically hit long-dormant addresses, indicating they had time to map vulnerable seeds before the sweep.
Drafted by a large language model from the source reporting linked above, then screened by automated publishing checks. It is not read by a journalist before publication. Some articles cite our Alpha Score. Verify prices and figures against the original source. Educational coverage, not personalized advice.