In a stunning security collapse, an attacker emptied nearly 600 Bitcoin wallets containing around $38 million within half an hour. The breach didn't rely on hacking into devices or phishing. Instead, it exploited a subtle error in Coldcard’s firmware that weakened the cryptographic seeds, turning supposedly uncrackable keys into guessable codes.
The Entropy Shortfall That Opened the Door
Coldcard’s hardware wallets, favored for their top-tier security and air-gapped design, have been generating seeds with far less randomness than promised since March 2021. The firmware mistake caused seed generation to draw from a software fallback instead of the intended hardware random number generator. This slashed seed entropy from 128 bits to roughly 40 bits for Mk3 models, making brute-force attacks feasible for a skilled adversary.
Later Coldcard models weren’t spared either. Mk4, Q, and Mk5 wallets suffered reduced entropy estimated around 72 bits, though still less vulnerable than Mk3. Unfortunately, patching the firmware can’t fix keys already created, meaning compromised wallets remain exposed.
AI: Both the Guardian and the Betrayer
The irony cuts deep: Coinkite, Coldcard’s manufacturer, had deployed AI tools to review their own firmware, yet this critical bug slipped through undetected. Meanwhile, the attacker reportedly leveraged AI to identify the exact vulnerability the company's AI failed to catch. This raises pressing questions about relying solely on automated audits for critical crypto security.
The attack unfolded swiftly on July 31, starting at 2:14 a.m. UTC, with around 500 wallets drained by 2:39 a.m., consolidating the stolen Bitcoin into a single address. Experts from other hardware wallet makers like Trezor, Ledger, and Block confirmed that their devices were unaffected, spotlighting the unique risk posed by Coldcard’s specific flaw.
This incident shakes the confidence of bitcoin maximalists and institutional custodians who have long trusted Coldcard as their go-to for isolated, open-source bitcoin security. It starkly illustrates how even long-standing, highly regarded hardware wallets can harbor grave vulnerabilities silently for years.
This material is for informational purposes only and does not constitute financial advice.


