SecurityBitcoin(BTC)

Coldcard Hack Drains $111M+ in Bitcoin From Long-Dormant Wallets

The Bitcoin community is reeling from what appears to be one of the most devastating hardware wallet exploits in the cryptocurrency's history. A firmware vulnerability in Coldcard Mk3 devices has enabled sophisticated attackers to drain an estimated $111 million in Bitcoin from unsuspecting holders, with researchers warning the final tally could surpass $130 million as investigations continue.

The breach, which began last Thursday, has sent shockwaves through the self-custody ecosystem that many Bitcoiners consider the gold standard for security. What makes this attack particularly alarming is its systematic targeting of long-dormant wallets—the very coins that security-conscious investors had tucked away for years, trusting their hardware wallet to keep them safe.

The Technical Failure Behind the Breach

At the heart of this catastrophic security failure lies a seemingly innocuous firmware bug that has persisted for over five years. According to Coinkite, the company behind Coldcard, a flaw introduced in firmware version 4.0.1—released in March 2021—caused seed phrase generation to default to a weak software-based Pseudorandom Number Generator (PRNG) instead of utilizing the device's hardware true random number generator (TRNG).

This distinction is critical. Hardware random number generators derive entropy from physical processes that are genuinely unpredictable, while software PRNGs follow deterministic algorithms that, given enough information, can be reverse-engineered. The bug essentially transformed what users believed was cryptographically secure randomness into a predictable pattern that attackers could exploit.

The vulnerability allowed hackers to essentially reconstruct seed phrases—the master keys to Bitcoin wallets—by exploiting the weakened randomness. Once in possession of these seed phrases, attackers gained complete control over victims' funds, transferring Bitcoin to their own wallets in a theft that continued throughout the weekend as the community scrambled to respond.

Coinkite acknowledged in a statement that the bug "silently went unnoticed" and "its potential impact grew with every release" of subsequent firmware updates. This admission raises troubling questions about the company's security auditing processes and the broader hardware wallet industry's quality assurance standards.

Victim Analysis Reveals Disturbing Patterns

Research conducted by Galaxy Research's Alex Thorn offers a stark picture of the attack's impact. Analysis of 250 victim reports reveals that the hackers specifically targeted—or were able to access—long-dormant wallets, with the typical stolen Bitcoin having sat untouched for 3.5 years. A staggering 88% of pilfered funds came from wallets that had been inactive for at least one year.

This pattern suggests the attackers may have systematically worked through vulnerable addresses, prioritizing those showing signs of long-term holding behavior. For many victims, these were savings they had carefully set aside for years, potentially earmarked for major life events or Bitcoin retirement planning.

The loss distribution paints a picture of concentrated pain among dedicated Bitcoin holders:

  • Median individual loss: 1.022 BTC
  • Average individual loss: 4.04 BTC
  • Largest single loss: 58.97 BTC
  • Median loss per address: 0.014 BTC
  • Mean loss per address: 0.212 BTC

The disparity between median and mean losses indicates that while most victims lost around one Bitcoin, a smaller number of high-value holders suffered disproportionately larger thefts, skewing the average significantly higher.

The Race to Secure Remaining Funds

As news of the exploit spread last Thursday, a frantic scramble ensued among Coldcard Mk3 owners to secure their holdings. Coinkite and prominent Bitcoin community members urged users to immediately transfer their funds to secure storage, whether to updated hardware wallets, multisignature setups, or even exchanges as a temporary measure.

The irony of cautious self-custody advocates moving coins to centralized exchanges—traditionally viewed as security risks in their own right—was not lost on observers. Yet for many, the immediate threat posed by the Coldcard vulnerability outweighed the counterparty risks of exchange custody.

Galaxy Research confirmed Friday that while $111 million in losses had been verified, their investigation was far from complete. "We have many more coins we are vetting for confirmation—we think total losses likely exceed $130 million," the firm stated on X, indicating the full scope of the damage remains unknown.

The theft continued throughout the weekend as attackers apparently worked through a list of vulnerable addresses before owners could react. This extended attack window highlights the challenges of coordinating emergency responses in a decentralized ecosystem where not all users actively follow community news or social media updates.

Broader Implications for Hardware Wallet Security

This incident strikes at the foundation of the "not your keys, not your coins" philosophy that has defined Bitcoin security culture. Hardware wallets like Coldcard have long been recommended as the safest method for storing significant Bitcoin holdings, specifically because they generate and protect private keys in isolated, secure environments.

The revelation that a critical security component—random number generation—could silently fail for over five years without detection raises uncomfortable questions for the entire industry. If Coldcard, widely regarded as among the most security-focused hardware wallet manufacturers, could ship devices with such a fundamental flaw, what vulnerabilities might lurk in competing products?

Security researchers will likely scrutinize other hardware wallets with renewed intensity following this breach. The incident may also accelerate adoption of multisignature setups, which require multiple keys to authorize transactions and could have prevented single-point-of-failure thefts like this one.

For the affected victims, the losses are permanent. Unlike traditional financial crimes where banks or insurers might provide recourse, Bitcoin transactions are irreversible by design. The stolen funds have almost certainly been mixed or moved through various obfuscation techniques, making recovery virtually impossible.

Market Response and Path Forward

Remarkably, Bitcoin's price has shown resilience in the face of this security crisis. Related reporting indicates the cryptocurrency has "chopped higher" as investors continue purchasing through ETF products, with nearly $800 million in inflows recorded in the wake of the exploit.

This market behavior suggests that while the Coldcard hack represents a serious blow to affected individuals and raises valid concerns about hardware wallet security, the broader investment thesis for Bitcoin remains intact for most market participants. The incident is being treated as a specific product failure rather than a systemic cryptocurrency vulnerability.

Coinkite faces a challenging road ahead. The company must not only address the immediate technical issues but also rebuild trust with a community that placed its faith—and in many cases, life savings—in Coldcard's security promises. Whether through compensation programs, enhanced security audits, or fundamental changes to their development processes, the company's response will determine its future in the competitive hardware wallet market.

Lessons for the Self-Custody Community

The Coldcard breach offers painful but valuable lessons for Bitcoin holders. First, no single security solution should be treated as infallible. Even products with strong reputations and dedicated security teams can harbor critical vulnerabilities. Diversification of custody solutions, including multisignature arrangements, provides protection against single points of failure.

Second, staying informed about security advisories and maintaining current firmware—while clearly insufficient in this case—remains essential. Victims who learned of the exploit early and acted quickly may have preserved their holdings.

Finally, the incident underscores the importance of the broader security research community. The discovery and disclosure of this vulnerability, though it came too late for many victims, demonstrates the ongoing need for independent security auditing of cryptocurrency infrastructure.

As investigations continue and the final damage tally emerges, the Bitcoin community must grapple with uncomfortable truths about the state of self-custody security. The dream of being one's own bank carries responsibilities that many may be ill-equipped to handle—and risks that even the most careful may not fully appreciate until it's too late.

Want to buy Bitcoin safely?

Use a regulated exchange with the best security.

Open Binance Account →

Free 7-Day Bitcoin Course

Everything you need to start with Bitcoin — one lesson per day, from someone who's lived on it since 2013.

No spam. Unsubscribe anytime. Free forever.