Coldcard Bitcoin Hack Hits $114 Million: What Happened

A firmware flaw inside one of Bitcoin’s most trusted hardware wallets has triggered one of the biggest self-custody thefts in crypto history. Coldcard, made by Coinkite, is now at the center of a rolling attack. Hackers have drained an estimated $114 million in Bitcoin since Thursday, July 30.

According to Galaxy Research, the running total has climbed past 1,800 BTC. That amount was stolen from more than 5,200 addresses across four separate waves of attacks. Alex Thorn, the firm’s head of research, flagged a fourth wave early Monday. He tracked sweeps happening at roughly 45 times the normal rate for that kind of transaction.

So what actually went wrong? The root cause traces back to a firmware update from March 2021. Coinkite confirmed that a bug in Coldcard Mk3 devices, starting with version 4.0.1, caused a serious problem. The wallet began generating seed phrases using a weak software random number generator. It should have used the device’s built in hardware randomizer instead. That single mistake shrank what should have been unguessable, 128 bit security down to something attackers could brute force offline.

In plain terms, the keys were supposed to be mathematically impossible to guess. Instead, they turned out to be predictable. Anyone who worked out the pattern could recreate a victim’s private key. They could do this without ever touching the physical device. As a result, the entire point of an air gapped cold wallet was bypassed.

This is what makes the incident so unsettling for the crypto industry. Hardware wallets like Coldcard have long been sold as the gold standard of self-custody. They are supposed to be the safest alternative to leaving funds on an exchange. However, victims in this case did everything right. They bought directly from the manufacturer. They kept their devices offline. They verified their firmware. Still, they lost their coins.

Coinkite has since admitted that all of its device models were affected, not just the Mk3. The company destroyed its remaining inventory built with the vulnerable firmware. Shipments have been halted. Meanwhile, emergency firmware has been released for every impacted model. Coinkite is now urging all affected users to move their funds immediately to a wallet generated with a fresh seed phrase.

There is also a striking twist to how the flaw was likely discovered. Coinkite says it has to assume the attacker used artificial intelligence to scan its open source firmware code. Notably, the company’s own AI assisted review of that same code weeks earlier failed to catch the bug. Thorn described the pattern of the sweeps as looking programmatic. In his view, they were likely coordinated with the help of a large language model. Both sides, defenders and attackers, appear to have had access to similar tools. This time, though, the tool worked for the attacker first.

ALSO READ ABOUT:Crypto’s Boom and Bust Cycle Claims Another Casualty as Market Volatility Continues to Shake the Industry

Engineers at payments company Block investigated the breach alongside independent researchers. Together, they traced the flaw to a specific code change from March 1, 2021 that altered how Coldcard generated seeds. They also found that the attacker used a major blockchain services provider to help move the stolen funds. That provider has since been contacted, along with federal authorities.

Not every part of the fourth wave has been confirmed as tied to the exploit. Still, researchers note something useful for victims. The newest transactions used Bitcoin’s replace by fee feature. This means some victims who spot their coins sitting unconfirmed in the mempool may still have a narrow window. They could outbid the attacker and rescue their funds before the theft is finalized.

The timing has also raised eyebrows across the industry. The Coldcard breach comes just months after a separate incident in January. Back then, thieves stole $282 million in Bitcoin and Litecoin through a social engineering scam aimed at hardware wallet users. That earlier attack relied on tricking victims. This one did not need to trick anyone at all.

For an industry built on the phrase “not your keys, not your coins,” the Coldcard incident cuts at something deeper than a single company’s mistake. It shows that even users who followed every recommended security practice can still be exposed. The flaw was buried inside the very hardware meant to protect them. Coinkite has openly acknowledged the scale of the damage. The company called the past few days among the hardest in its history, admitting that trust built over years was broken in a matter of days.

Investigators, researchers, and Coinkite itself are continuing to monitor wallets that may still be vulnerable. They warn that any device running the flawed firmware could eventually be targeted, unless funds are moved to a securely regenerated seed.

Leave a Reply

Your email address will not be published. Required fields are marked *

Previous Post

Nigeria Introduces First Tax Framework for Crypto and Virtual Assets

Next Post

5G Gap Leaves Millions Of Devices Offline

Related Posts