
The Coldcard hack traces to a weak random number generator that left seeds with as little as 40 bits of entropy. Coinkite's patch does not fix exposed seeds.
Thousands of Bitcoin addresses secured by Coldcard hardware wallets were drained through a firmware flaw. Galaxy Digital put confirmed losses at about 1,719 BTC, or $100 million to $111 million. Coldcard version 4.0.1, shipped March 17, 2021, was the release that introduced the weakness.
The victims did everything right. No phishing. No leaked recovery phrase. The firmware itself was broken, and the flaw went undetected for more than five years.
Alex Thorn of Galaxy Digital's on-chain analysis team confirmed the findings through on-chain forensics. The report, the most detailed independent account of the breach so far, identified roughly 7,300 targeted addresses and at least 15 distinct attackers.
The bug sat inside the device's random number generator. Version 4.0.1 produced wallet seeds with far less entropy than expected, in some cases as little as roughly 40 bits. A standard wallet seed carries at least 128 bits of entropy and sits beyond brute-force reach. A 40-bit seed does not. Attackers used open-source brute-force tools to reconstruct the affected seeds and drain the wallets they controlled.
Coinkite, the maker of Coldcard, disclosed the vulnerability on July 30 and released a patched firmware version the next day. Patching a device does not recover lost funds, and it does not fix seeds already generated on vulnerable firmware. Affected users need to generate entirely new seeds on updated firmware and transfer all funds to new addresses.
Galaxy documented the exploitation as a series of theft waves. The confirmed losses run between about 1,596 BTC and 1,719 BTC. Three confirmed waves preceded a suspected fourth around Aug. 3 that added roughly 389 BTC. The fourth wave arrived after both the disclosure and the patched release. By Aug. 7, confirmed stolen Bitcoin stood at 1,719 BTC. Some reports put potential total losses above $130 million once additional suspected activity was included.
Galaxy read the sequence as coordinated exploitation rather than one opportunistic actor who found the bug independently. Galaxy's identification of at least 15 distinct attackers suggests the vulnerability was shared or sold among a group before public disclosure.
Most of the stolen Bitcoin remains unspent on-chain. Thorn said the attackers have moved the funds without converting or dispersing them through typical laundering patterns. The coins sit outside exchanges and mixers. Thorn said that could change at any time.
Hardware wallets sell on one promise: keys offline, Bitcoin safe. Coldcard's reputation rested on being among the most security-conscious devices available. Its users skew toward technically sophisticated Bitcoin holders who chose self-custody over exchange storage.
The people most committed to controlling their own keys ended up exposed by the tool they trusted to protect those keys.
Any Coldcard running firmware 4.0.1 or later carries the exposure, including devices updated in the five years since the bug shipped. For users still holding funds on those versions, the next step is to update the firmware and migrate to a freshly generated seed. Waiting adds risk. Galaxy said the suspected fourth wave suggests the exploitation window may still be open for affected addresses that have not been drained.
Coinkite has not said whether affected users were notified individually before the July 30 disclosure and has not responded to requests for comment.
Drafted by a large language model from the source reporting linked above, then screened by automated publishing checks. It is not read by a journalist before publication. Some articles cite our Alpha Score. Verify prices and figures against the original source. Educational coverage, not personalized advice.