COLDCARD Hardware Wallet Flaw Exposes Bitcoin to $70 Million Theft, Users Must Update

Approximately 594 BTC (about $38 million) were drained from around 500 COLDCARD wallets in a 25-minute window (01:31–01:56 UTC) on July 30.
The root cause traces to a March 2021 firmware update (version 4.0.0) that disabled the hardware RNG on affected COLDCARD devices, replacing it with a predictable software fallback seeded with device metadata; this allowed seeds to be derived and brute-forced, primarily affecting Mk3 models and some Mk2 units.
Investigators traced the attacker’s on-chain activity to a blockchain services provider via paid service usage during the sweeps; authorities were alerted, and researchers described unusual movement patterns that supported attribution to a single actor.
Guidance on fixes evolved: initial reporting suggested newer models (MK4, MK5, Q) were not affected, but later advisories indicated all COLDCARD models could be vulnerable; fixed firmware versions include Mk3 4.2.0+, Mk4/Mk5 5.6.0+, and Q 1.5.0Q+; even after updating, seeds created under the compromised firmware remain vulnerable, necessitating new wallets and on-chain migrations.
The scale of the theft has been reported variably: initial figures cited around $38 million (594 BTC), but subsequent reporting has pushed totals toward more than $70 million, with over 1,000 BTC stolen and researchers noting patterns that suggested an operator targeting multiple addresses and preferring single-signature wallets.
Attackers drained more than 1,000 Bitcoin — worth roughly $70 million — from nearly 1,196 Coldcard hardware wallets in a 41-minute window on July 30, according to Crypto News. The theft exploited a five-year-old firmware bug that made wallet seed phrases predictable, allowing hackers to recreate private keys without ever touching the physical devices.
The root cause traces to a March 2021 firmware update (version 4.0.0) that disabled the hardware random number generator on Coldcard devices. Instead of true randomness, the firmware fell back to a software-based generator seeded with predictable device metadata — making many wallet keys possible to guess through brute force.
The first wave of thefts hit between 01:31 and 01:56 UTC on July 30. In that 25-minute span, attackers swept approximately 594 BTC — about $38 million — from around 500 Coldcard wallets, according to Krypto News. Chainalysis noted the hacker targeted the largest wallets first, maximizing losses before moving down the list.
The attack then continued. Crypto News reported that the final tally reached 1,082 BTC stolen from 1,196 wallets over roughly 41 minutes — nearly double the amount first reported. Researchers noted the attacker showed a clear preference for single-signature wallets, which offered no multi-party protection against the compromised keys.
A hardware wallet's security depends on generating a truly random seed phrase. Coldcard's version 4.0.0 firmware, released in March 2021, broke that process. It disabled the dedicated hardware random number generator (RNG) and replaced it with a software fallback. That fallback used non-secret device metadata as its starting point — making the output far easier to predict.
The affected models were primarily Mk3 devices running firmware versions 4.0.1 through 4.1.9, with some Mk2 units also impacted, according to Head Topics. Coinkite, the maker of Coldcard, initially said newer models — Mk4, Mk5, and Q — were not affected. Later advisories walked that back, warning all Coldcard models could carry some risk.
Blockchain researchers were able to trace the attacker's movements using on-chain patterns. Crypto News reported that the hacker's use of paid blockchain services during the sweeps left a trail that linked the activity to a specific blockchain services provider. Investigators described the patterns as consistent with a single operator running a coordinated sweep.
Authorities were alerted following the analysis. Bloomingbit reported that the unusual movement of funds — hitting many addresses in a short, structured window — helped researchers build an attribution case. Galaxy Research also contributed analysis that helped clarify the full scope of the theft.
Coinkite released patched firmware to fix the RNG flaw. The fixed versions are Mk3 4.2.0 or higher, Mk4 and Mk5 version 5.6.0 or higher, and Q version 1.5.0Q or higher. Users should update immediately. But updating alone is not enough — any seed phrase created under the broken firmware is still compromised.
Advisories urged users to generate a completely new seed on safe, unaffected hardware and move all funds to a new wallet address on-chain. Traders Union described one real-world case where a Bitcoin holder successfully migrated funds off a vulnerable Coldcard device with help from the community, avoiding loss. Experts warned that skipping the migration step leaves money at permanent risk, even after the update.
Publishers
129
Articles
46
Reach
175