A significant security vulnerability in Coldcard hardware wallets has led to the theft of 594.48 BTC, valued at approximately $38.3 million, from over 500 Bitcoin addresses. The breach has triggered a wave of concern among cryptocurrency investors and renewed debates regarding the reliability of popular hardware wallets for digital asset protection.
Coldcard wallet flaw exposes critical vulnerabilities
Coldcard, developed by Coinkite, is a widely used hardware wallet for securing Bitcoin. According to security firm Block Security, a flaw in the wallet’s firmware has left nearly all Coldcard models—Mk2, Mk3, Mk4, Q, and Mk5—exposed to automated attacks. Block Security stated that the issue has persisted in Coldcard firmware since March 2021.
The fundamental issue stemmed from problems with the wallet’s seed phrase generation process. In older models, a malfunction in the code disabled the device’s hardware random number generator, forcing it to rely on a less-secure, predictable software algorithm. Newer devices encountered a separate flaw, where essential portions of the entropy data were inadvertently truncated during the process.
These flaws dramatically reduced the number of possible combinations for secret seed phrases, making it feasible for attackers to brute-force the wallet’s private keys using conventional computers. As a result, hackers successfully carried out an automated attack, emptying more than 500 Bitcoin addresses and consolidating the funds into a single wallet.
Mini dictionary: Seed phrase, a series of words generated by a cryptocurrency wallet that represents the wallet’s master private key and is essential for asset recovery.
| Coldcard Model | Main Flaw |
|---|---|
| Mk2 / Mk3 | Hardware RNG disabled, predictable seed phrase |
| Mk4 / Q / Mk5 | Critical entropy data truncated during generation |
Community and expert reactions
Well-known Bitcoin developer Peter Todd, who once appeared in an HBO documentary that speculated on the identity of Bitcoin creator Satoshi Nakamoto, reacted strongly to the incident. Todd has consistently questioned the safety of hardware wallets within the cryptocurrency sector, emphasizing concerns about their closed-source codebases and potential for supply chain vulnerabilities.
I’ve always been skeptical of hardware wallets. You pay a lot of money for a device running code that few people will ever look at, on hardware that could be backdoored with a supply chain attack.
Todd explained that the recent breach highlights the dangers of insufficient independent review and lack of thorough auditing for hardware wallet software. He advocated for the adoption of end-to-end deterministic testing of physical devices to ensure true randomness in key generation. He also referenced methods like using physical randomization techniques, such as a deck of cards, or alternative proposal like his previously shared button-based random number generator (RNG).
Mini dictionary: RNG (Random Number Generator), a system used to create unpredictable numbers required for cryptographic key generation and security.
Broader security risks for users
The vulnerability affects not only standard single-key wallets but also multisignature wallets if all signature keys were created using impacted Coldcard devices. According to Block Security, the breach occurs at the moment a seed phrase is generated, meaning that exporting the compromised seed to another wallet or device does not resolve the problem. Assets remain at risk until new, truly random seed phrases are generated and funds are moved accordingly.
Experts are urging Coldcard users to generate new seed phrases on verified third-party hardware and physically transfer all Bitcoin holdings to new secure addresses. Those who created an additional BIP-39 passphrase during their Coldcard setup appear to have an extra layer of defense, as this password works as a second obstacle against brute-force attacks.
Only users who added an extra BIP-39 passphrase during setup remain protected, as it creates another barrier against brute-force attempts.




