CRYPTO

Coldcard Exploit Hits $70M; Firmware Patch Issued

person holding black and white p print box

A firmware entropy flaw in Coinkite’s Coldcard hardware wallets has led to the confirmed theft of more than 1,082 BTC, worth approximately $70 million, after attackers brute-forced private keys generated by a defective pseudorandom number generator. The breach began July 30 and expanded rapidly across all Coldcard models before a firmware patch was issued on July 31. Authorities have been notified, and on-chain forensics are active.

How the Entropy Flaw Enabled the Drain

The root cause was a specific code defect in Coldcard Mk3 firmware versions 4.0.1 through 4.1.9, first shipped in March 2021. Instead of drawing from the device’s hardware true random number generator, seed creation fell back silently to a software pseudorandom number generator, reducing effective entropy to roughly 40 bits rather than the intended 128. That gap made private keys for single-signature wallets predictable enough to brute-force at scale, particularly for seeds created without dice rolls or a BIP-39 passphrase. Later updates expanded the scope: Coinkite confirmed that Mk4, Mk5, and Q devices were also affected, though with marginally higher entropy of around 72 bits rather than the expected 128.

Chainalysis reported that the attacker prioritized wallets by balance, sweeping roughly $30 million within the first ten minutes alone. In total, 1,196 addresses across four consecutive blocks were drained in the opening wave. Clay Garrett, an engineer at payments company Block, said on X that investigators identified a repeating pattern in the sweeps that pointed to a paid account at a well-known blockchain services provider: “That pattern led us to a hypothesis that has since been confirmed: the operator used a paid account at a well-known blockchain-services provider to query the source addresses and perform other related activity during the sweeps.” Galaxy Digital’s research team confirmed the same attacker signature, noting that the movement pattern itself was distinctive even though the individual transactions appeared indistinguishable from normal owner-initiated transfers. Industry experts have also indicated AI-assisted tooling was likely involved in accelerating the key searches, though that attribution remains unconfirmed.

Market OverviewTop 10 by market cap
1BTCBitcoin BTC$62,992.00▼2.00%
2ETHEthereum ETH$1,868.09▼1.70%
3USDTTether USDT$0.9991▲0.00%
4BNBBNB BNB$589.31▲0.30%
5USDCUSDC USDC$0.9996▲0.00%
6XRPXRP XRP$1.07▼1.40%
7SOLSolana SOL$73.05▼1.40%
8TRXTRON TRX$0.3267▼0.60%
9FIGR_HELOCFigure Heloc FIGR_HELOC$1.02▼2.20%
10HYPEHyperliquid HYPE$52.28▼4.80%

Patch Details and What Affected Users Must Do

Coinkite released fixed firmware on the morning of July 31. Mk4 and Mk5 users must update to version 5.6.0 or later; Q users to version 1.5.0Q or later; Mk3 users to version 4.2.0 or later. Critically, updating firmware does not secure an existing seed: any seed generated on a vulnerable firmware version remains compromised, and funds must be moved to a freshly generated wallet on the patched device. Bitcoin developer Peter Todd flagged an additional edge case for multisig holders, warning that users with two compromised Coldcard keys in a 2-of-3 setup should use MARA Pool’s private mempool service Slipstream to keep the redeem script hidden until confirmation.

At time of writing, Bitcoin’s network hash rate sits at 960.1 EH/s with 497,475 active addresses in the prior 24 hours, and the chain is 89,525 blocks from the next halving. The protocol itself is intact; this breach sits entirely in the firmware supply chain. That distinction matters. Self-custody remains the architecturally superior model, but incidents like this one confirm that firmware verification and open, auditable build processes are not optional features. They are the foundation the entire trust model rests on, and right now that foundation cracked. Every Coldcard user with a seed generated after March 2021 who did not use 50-plus dice rolls should treat that wallet as compromised and act immediately.

Alyssa Monroe

I track the technology that powers crypto. Layer 1 networks, scaling layers, developer ecosystems and the infrastructure quietly expanding what blockchains can do. Ethereum, Solana, Avalanche, Polkadot. Rollups, Lightning, cross-chain systems, tokenised assets. Markets chase price. I watch builders, protocol upgrades and the milestones that signal real adoption.

You may also like...

Leave a Reply

Your email address will not be published. Required fields are marked *