Hackers drained nearly $70 million in bitcoin from hundreds of Coldcard hardware wallets on July 30, exploiting a critical vulnerability in the wallet’s seed generation process. The attack lasted just under 25 minutes but spread across more than 1,100 addresses within 41 minutes, according to Galaxy Research’s investigation.
Firmware Flaw Undermined Bitcoin Security
The root of the breach lies in Coldcard's Mk3 wallets, produced by Canadian company Coinkite. While these devices are known for their air-gapped design to prevent online exposure, a flaw introduced in firmware versions released since March 2021 severely weakened the random number generator used to create wallet seeds. Instead of the promised 128 bits of entropy, the seeds contained only about 40 bits, drastically shrinking the pool of possible combinations and enabling attackers to guess seeds and steal funds.
Many affected wallets belonged to holders who had left their bitcoin untouched for years. The attacker moved swiftly, paying high fixed transaction fees and emptying each wallet completely without leaving change outputs. The pattern implies an automated, premeditated operation, rather than a hack resulting from malware or physical device theft.
Coinkite has urged users to immediately update their firmware and generate new recovery seeds before transferring any funds. As investigators continue to track the stolen bitcoins through the public ledger, the full scale of losses may evolve. So far, 1,083 BTC went missing from roughly 1,196 wallets.
This breach highlights how critical proper seed entropy is for hardware wallets, even those with advanced security features. The incident raises questions about the long-term safety of dormant bitcoin addresses created with vulnerable firmware.
This material is for informational purposes only and does not constitute financial advice.


