Coldcard, a producer of Bitcoin hardware wallets manufactured by Coinkite, is facing mounting losses as a critical firmware flaw has enabled a series of large-scale thefts. Galaxy Research, a blockchain analysis firm, reported that a fourth wave of attacks occurred over the weekend, resulting in the unauthorized transfer of 448.7 Bitcoin from 709 addresses suspected to belong to affected users.
Widespread Losses and Ongoing Vulnerability
Across all four attack waves, Galaxy Research estimates that 1,815 Bitcoin has been drained from 5,294 addresses. This figure is based on observed transaction patterns and does not account for overlapping victims, nor is it officially confirmed by Coinkite or law enforcement. Alex Thorn, head of research at Galaxy, labeled the addresses as “likely Coldcard victims” based on their transaction behavior, rather than direct confirmation from device records.
The timing and structure of many attacks suggest a coordinated effort to exploit vulnerable wallets before their owners could update firmware or secure funds. Coinkite has not confirmed the exact scale of the losses, but the ongoing risks have prompted urgent warnings from the security community.
Despite multiple waves of thefts, some suspicious transactions remain unconfirmed and are still visible in Bitcoin’s memory pool, offering a potentially brief window for users to recover their funds by issuing a replacement transaction with a higher fee.
Origins of the Security Flaw
Coinkite attributes the issue to a cryptographic library change applied in March 2021. This update inadvertently routed wallet seed creation to a software-based random number generator instead of using the secure hardware-based system the device was designed for. According to Coinkite’s internal report, the weaker generator existed in the code base and was triggered without the team’s awareness, leading to a significant decrease in wallet seed entropy.
Multiple versions of the Coldcard hardware—including Mk2, Mk3, Mk4, Mk5, and the Q—were affected, with each model experiencing varying degrees of reduced randomness in seed generation. Block, a financial services and digital payments firm, verified that the firmware had relied on the fallback generator, and agreed that prompt disclosure was vital in light of the mounting theft reports, even without full testing to determine the exploitability of the flaw.
Mini dictionary: Entropy, in cryptography, refers to the randomness collected by a system for use in cryptographic operations, which is essential for generating unpredictable keys and seeds.
User Guidance and Response
Coinkite has issued fixed firmware for affected models, but the update does not fix wallets that have already generated seeds with insufficient entropy. Users who created wallets before the patch must generate new seeds using the updated firmware, test with a small transfer, and then move any remaining funds. Seeds made using at least 50 dice rolls or secured with a strong passphrase are not exposed to this specific vulnerability.
Kraken’s chief security officer, Nick Percoco, highlighted that the incident exposes the absence of independent and standardized testing for hardware wallets—a practice already common with other cryptographic devices. He emphasized the need for the industry to implement verification standards to ensure the correct random number generators are operational in production units.
The Coldcard flaw reveals a significant oversight in hardware wallet verification, calling attention to the industry’s lack of established standards for independent testing of cryptographic components.
Coinkite responded by halting all Coldcard shipments, destroying unsold devices running the vulnerable firmware, and urging affected users not to discard their hardware, as these could aid in future investigations and fund recovery efforts.
The company also stated that its legal team will collaborate with law enforcement agencies in multiple jurisdictions as the investigation progresses.
| Attack Wave | Bitcoin Stolen | Addresses Affected |
|---|---|---|
| First–Third Waves | 1,366.3 BTC | 4,585 |
| Fourth Wave | 448.7 BTC | 709 |
| Total | 1,815 BTC | 5,294 |




