News View Non-AMP

Coldcard Wallet Flaw Exposed? Hacker Quietly Drains 1,082 BTC Before Security Warning

Published by
Rizwan Ansari

A firmware flaw that remained unnoticed for years has resulted in one of the largest Bitcoin hardware wallet thefts in recent months. More than 1,082 BTC, worth around $70 million, was quietly stolen from over 1,100 wallets before the wallet maker publicly warned users about the security issue.

Old Firmware Bug Allowed Hacker to Recreate Bitcoin Wallet Keys

According to research from Galaxy Research, the attacker drained 1,196 Bitcoin addresses between 01:10 and 01:51 UTC on July 30, emptying around 1,082.65 BTC within just 41 minutes. The attack happened almost 30 hours before wallet manufacturer Coinkite publicly warned users that certain Coldcard devices could be vulnerable.

Rather than hacking the devices directly, researchers believe the attacker recreated wallet private keys offline by exploiting a weakness in how some Coldcard wallets generated recovery seed phrases.

The attack targeted wallets created on Coldcard Mk3 devices running firmware versions 4.0.1 through 5.0.3, originally released in March 2021.

Galaxy Research noted that every transaction used the same unusually high 30 sat/vB transaction fee and left no change output, suggesting the attacker already possessed the private keys and simply automated the withdrawals.

How the Coldcard Bug Weakened Wallet Security

Security researchers explained that the issue began with a firmware update released in 2021.

Hardware wallets normally generate recovery phrases using a dedicated hardware random number generator, making wallet keys practically impossible to guess. However, engineers at Block found that a coding mistake accidentally disabled this hardware randomness on affected devices.

Instead, wallets relied on a software-based random number generator using predictable information such as the device serial number and internal clock.

This reduced the effective security of wallet seed phrases from the expected 128 bits of entropy to around 40 bits on affected Mk3 devices, making large-scale brute-force attacks possible with modern computing power.

Coinkite later expanded the warning to include certain Mk4, Mk5 and Coldcard Q firmware versions, where entropy was reduced to around 72 bits, although the company said newer hardware architecture significantly reduced the overall risk.

Millions in Bitcoin Remain Frozen

The stolen Bitcoin was quickly consolidated into several wallets, with researchers identifying one address that still holds more than 562 BTC. Other wallets contain 398 BTC, 89 BTC, and 32 BTC, with none of the funds moving after consolidation.

Coinkite has urged anyone who generated a recovery phrase on affected firmware to immediately move funds to a newly created wallet using the latest firmware.

The company also noted that users who protected their wallets with an additional BIP-39 passphrase face much lower risk because the extra passphrase adds another security layer beyond the compromised seed.

Security experts believe the attacker likely generated millions of possible wallet keys in advance and simply waited for matching wallets to appear on the Bitcoin network, warning that additional vulnerable wallets could still be at risk if owners do not migrate their funds.

Rizwan Ansari

Rizwan is an experienced Crypto journalist with almost half a decade of experience covering everything related to the growing crypto industry — from price analysis to blockchain disruption. During this period, he’s authored more than 3,000 news articles for Coinpedia News.

Recent Posts

Bitcoin Price News: The Hidden Number Deciding If Altcoins Rally Next

Bitcoin is trying to stay above the $83,000 level, and according to a technical analyst…

September 30, 2026

ZEC Price Consolidates as Whales Accumulate—Is Zcash Heading to $2000 in October?

The Zcash (ZEC) price is nearing the end of the September trading period after a…

September 30, 2026

NewGenIvf Sold Entire XRP Holdings Before Year-End, SEC Filing Shows

Nasdaq-listed IVF company NewGenIvf (NIVF) disclosed in an SEC filing that it purchased 146,432 XRP…

September 30, 2026

Bitwise CIO Names His ‘Mount Rushmore’ Of Crypto, Says These 4 Coins Are Driving Bull Market

While everyone's watching Bitcoin, one expert says there are 4 other assets quietly leading this…

September 30, 2026

Brad Garlinghouse Says XRP Has a Specific Role in Ripple’s Payments Strategy

Ripple CEO Brad Garlinghouse has outlined the company’s approach to XRP, cross-border payments and the…

September 30, 2026

Crypto Market Cap Breakout Signals End of 2026 Accumulation

The crypto market cap is finally moving beyond the accumulation range that has defined much…

September 30, 2026