Coldcard wallets have been at the center of a major security incident after a vulnerability allowed hackers to steal 1,367 BTC, worth roughly $88.6 million. The issue originates from a firmware update rolled out in March 2021, which introduced weak randomness in generating seed phrases. This weakness gave attackers the ability to predict users’ seed phrases and drain funds.
The attacks happened in three distinct waves. Galaxy Research tracked these on-chain, identifying 4,585 affected addresses tied to Coldcard devices from Mk2 through Mk5 models. The latest wave alone saw a loss of 207 BTC. This flaw severely compromises the security guarantees that hardware wallets are supposed to provide.
Users are strongly advised to create new seed phrases on updated Coldcard firmware or switch to alternative hardware wallets. However, even moving funds from vulnerable wallets carries risk. Experts warn that attackers may intercept transactions by outbidding fees, seizing coins mid-transfer. Using out-of-band transaction submission methods is recommended to avoid such interception.
Bitcoin’s price hovered near $62,996 as the exploit fueled more anxiety in a market already leaning toward fear. The incident highlights ongoing challenges in securing crypto assets despite hardware wallet adoption. For those tracking overall crypto risks, this event echoes concerns similar to other recent security issues in the ecosystem.
This material is for informational purposes only and does not constitute financial advice.



