A major security breach has shaken the Bitcoin community, as more than $70 million in Bitcoin was stolen following an exploit targeting Coldcard hardware wallets. Investigations indicate that the attacker relied on one of the industry’s leading blockchain services providers to facilitate the theft.
Unusual transaction patterns alert investigators
Clay Garrett, an engineer at payments technology company Block, stated that after detecting suspicious Bitcoin movements, the team reached out to a prominent blockchain services provider. Garrett reported that analysis of the transaction activity uncovered a distinctive pattern during the attacker’s sweeping of funds.
Garrett explained that this pattern led to the conclusion that the thief maintained a paid account with a well-known blockchain services provider. This enabled the individual to systematically query source addresses and perform related operations as part of the theft’s workflow. Authorities have been notified as part of the ongoing investigation.
Garrett described how the sequence of transactions revealed that “the operator used a paid account at a well-known blockchain-services provider to query the source addresses and perform other related activity during the sweeps,” noting that this has since been confirmed and law enforcement had been informed.
The blockchain services company’s name has not been revealed, per requests from its representatives. However, the transaction patterns have raised questions about the role such platforms might play in facilitating large-scale illicit movements of digital assets.
Galaxy Digital, a diversified financial services and investment management company focused on digital assets, also highlighted these transaction patterns. Its research division remarked that the attacker’s approach to moving coins was distinctive, though not unique enough to reveal the method used for the hack itself.
According to Galaxy Digital’s researchers, “The pattern tells us these were all the same attacker — it does not capture the attack itself, which looks the same as if a coin owner chose to move coins,” and advised Bitcoin users to transfer funds from single-signature Coldcard addresses into more secure custody solutions.
Coldcard vulnerability: Firmware bug exposed wallets
Coinkite, which manufactures the Coldcard hardware wallet, reported that a firmware bug in the Coldcard Mk3 devices enabled the breach. The flaw, introduced with version 4.0.1 in March 2021, caused the devices to rely on a weaker software-based Pseudorandom Number Generator (PRNG) for seed creation, instead of a hardware-based true random number generator. This made it possible for attackers to predict wallet seeds and brute-force private keys, especially for accounts lacking dice roll entropy or a robust BIP-39 passphrase.
Mini dictionary: Pseudorandom Number Generator (PRNG) — A software algorithm used to generate sequences of numbers that appear random but are actually determined by an initial value, making them less secure than true random number generators which use unpredictable physical processes.
Initially, Coinkite said that the vulnerability was confined to certain models and firmware versions. However, the company later admitted that all Coldcard models carried similar risks after additional thefts were discovered. The company has since advised users to update firmware and move assets from affected wallets.
| Device/Version | Vulnerability | Risk |
|---|---|---|
| Coldcard Mk3 (v4.0.1+) | PRNG bug in seed generation | High |
| Other Coldcard models | Similar vulnerabilities | High |
Warnings have been issued that additional Bitcoin wallets could still be at risk, as engineers continue to assess the extent of the compromise. To date, at least $70 million worth of Bitcoin has been siphoned from compromised wallets.
What is Coinkite?
Coinkite is a Canadian company specializing in Bitcoin security solutions, including cold storage hardware wallets such as Coldcard. Its products are widely used in the cryptocurrency sector for secure offline storage of digital assets.




