COLDCARD Hardware Wallet Flaw Linked to $88 Million Bitcoin Theft
Researchers have connected a flaw in the firmware of COLDCARD, a popular Bitcoin-only hardware wallet made by Canadian company Coinkite, to one of the largest cryptocurrency thefts of the year. According to blockchain analytics firm Galaxy Research, an initial wave of automated transactions on July 30 drained roughly 1,083 BTC — worth about $70 million at the time — from nearly 1,200 wallet addresses in just 41 minutes. Two further waves of theft identified over the following two days pushed the total to an estimated 1,367 BTC, or approximately $88.6 million, taken from more than 4,500 addresses.
Investigators at Block, working with outside researchers after reports of the thefts surfaced, traced the root cause to an integration error in COLDCARD’s random number generation code. Rather than drawing from the device’s dedicated hardware random number generator, an incorrect check caused affected firmware versions to fall back to a software-based generator seeded with predictable values, including the device’s microcontroller ID and system timing data. That predictability allowed attackers to reconstruct likely wallet seeds offline, match them against addresses visible on the blockchain, and derive the private keys needed to empty the wallets once a match was confirmed.
Blockchain analytics firm Chainalysis found that the thieves prioritized high-value targets, moving roughly $30 million in the first ten minutes alone, which suggests the affected wallets had been identified and studied in advance rather than attacked at random. Coinkite has since disclosed the flaw publicly, released patched firmware for the affected device generations, and destroyed any pending inventory still carrying the vulnerable software. Because updating the firmware does not retroactively secure a seed generated before the fix, the company is urging affected owners to migrate their funds to newly generated wallets rather than simply installing the update.
The incident underscores a recurring risk in hardware wallets: security depends not only on keeping a device physically safe, but on the integrity of the cryptographic randomness used to generate keys in the first place. Users of affected COLDCARD models who have not yet migrated their holdings are advised to treat their existing seeds as compromised.