Coldcard Wallet Flaw Drains $70M in Bitcoin
A critical randomness flaw in Coldcard hardware wallets has enabled the theft of $70 million in Bitcoin, shaking confidence in a primary self-custody security tool.
Hackers have stolen 1,082.65 Bitcoin, valued at over $70 million, by exploiting a seed generation flaw in Coldcard wallets produced by Coinkite. The attackers rapidly drained 1,196 addresses by brute-forcing private keys that lacked sufficient cryptographic randomness. Affected users reported funds that had sat dormant since 2021 suddenly being wiped out.
The vulnerability originated in a firmware update, version 4.0.1, deployed for the Mk3 model in March 2021. Instead of utilizing the device’s hardware true random number generator, the system silently fell back to a weak software alternative. This critical error reduced the cryptographic entropy from 128 bits to roughly 40 bits. Consequently, single-signature wallets became highly predictable if users did not manually add randomness via dice rolls or a BIP-39 passphrase.
Coinkite initially restricted its warnings to Mk3 users but escalated its guidance on Friday to include owners of the newer Mk4, Mk5, and Q devices. The company stopped short of explicitly confirming the theft is exclusively tied to its hardware. However, independent analysts at Galaxy Research and engineers at payments firm Block have directly linked the stolen funds to the faulty entropy issue. Blockchain data indicates the unauthorized drains are still ongoing.
For institutional and retail investors, this breach fundamentally undermines a core assumption of crypto markets: that dedicated hardware wallets provide impenetrable offline security. Coldcard is a widely respected and heavily utilized name in Bitcoin security. A failure of this magnitude within its trusted ecosystem forces a sector-wide reassessment of self-custody risk management.
Security professionals are urging immediate intervention, with some advising investors to abandon Coldcard devices entirely to ensure asset safety. The severity of the situation was summarized by Kevin Loaec, CEO of Bitcoin security firm Wizardsardine. “Everything is fucked,” Loaec wrote. “Every single mnemonic generated [via a Coldcard] since 2021 will be public in the next few days,” he warned.
Coinkite is now instructing all users to transfer their funds to alternative storage immediately. For those who choose to continue using the hardware, the company mandates generating a completely new seed. This process requires users to manually input 50 dice rolls to guarantee sufficient entropy and prevent further exploitation.