Hackers have continued to exploit security flaws in Coldcard Bitcoin wallets, bringing total losses to more than $114 million as of this week. The attacks, targeting wallets produced by Canadian hardware company Coinkite, have persisted despite public warnings and urgent calls for users to secure their funds.
Fourth wave of attacks and scale of losses
A new wave of thefts likely began on Sunday evening, when 388.9 Bitcoins, valued at over $29 million, were moved in a series of suspicious transactions. Alex Thorn, head of research at Galaxy, reported the movement publicly and linked it to the ongoing security breach affecting Coldcard wallets.
The surge in thefts followed earlier attacks last Thursday, which saw hackers drain over $35 million from vulnerable wallets. According to Coinkite, the root of the problem was a firmware vulnerability in its Coldcard Mk3 devices, which affected versions dating back to March 2021. The flaw caused these devices to use a weak software-based pseudorandom number generator—rather than a secure hardware random number generator—to create wallet seed phrases. This weakness allowed threat actors to predict and steal users’ private keys.
The attacks continued through the weekend, intensifying concerns among Coldcard users and the wider Bitcoin community. Coinkite and security experts have recommended that users transfer their assets to new, secure wallets as soon as possible.
Mini dictionary: Pseudorandom Number Generator (PRNG) — A software algorithm that generates sequences of numbers that only appear to be random. Unlike true random number generators, PRNGs can be predicted if the underlying process is not robust, making them unsuitable for cryptographic applications requiring high security.
User impact and company response
Josef Tětek, Bitcoin analyst at wallet maker Trezor, noted that the largest affected address so far contained 51 Bitcoins, underscoring the scale of damage for some holders. Many Coldcard wallet users reportedly lost significant amounts, in some cases entire life savings, due to the vulnerability.
Money that took years to save, gone. Trust that took years to build, broken. That impact is real, and for some, the damage is permanent.
Coinkite has acknowledged that not only the Coldcard Mk3, but all its wallet models were susceptible to the same flaw. Engineers have issued warnings that all Bitcoin addresses connected to Coldcard wallets could be at ongoing risk until appropriate precautions are taken.
| Timeline | Event | Bitcoin Estimated Lost |
|---|---|---|
| Thursday (Start of hacks) | Initial wave | $35 million |
| Sunday | Fourth wave | $29 million |
| Total | All waves to date | $114 million |
The company announced on Sunday that all remaining Coldcard inventory produced with compromised firmware had been destroyed and that all shipments have been paused indefinitely. Coinkite, which provides several Bitcoin security products with Coldcard as their flagship hardware wallet, stated that it was undertaking difficult internal reviews in the aftermath of the incident.
Ongoing investigations and industry fallout
Security engineers from payments company Block examined the hack and discovered that the attackers had leveraged a major blockchain services provider to move stolen assets. Block’s team confirmed that both the provider and federal authorities have received detailed findings as part of the ongoing investigation.
The Coldcard incident has prompted renewed scrutiny of wallet generation practices across the crypto industry, underlining the importance of robust hardware security and independent audits for wallet manufacturers.




