Attackers drained at least 1,719 Bitcoin, valued at approximately $111 million, from Coldcard hardware wallets. Those are confirmed losses. Galaxy Research warns total losses may exceed $130 million. The exploit targets a firmware flaw in the Bitcoin-only device.
The first wave hit July 30: 1,082.65 Bitcoin, then worth $70.2 million, drained from 1,196 addresses in 41 minutes. TRM Labs puts the total scope at roughly 1,816 Bitcoin, valued at $116 million, pulled from over 5,200 addresses across four distinct waves.
The vulnerability traces to a firmware integration error introduced in March 2021. That flaw redirected seed generation to a deterministic software pseudorandom number generator, bypassing the device's hardware random number generator—cutting the randomness required for secure private key generation.
The problem: Coldcard's production configuration defined MICROPY_HW_ENABLE_RNG as zero. The libngu library checked only for the macro's presence, not its active state. That logic error forced the system to use MicroPython's Yasmarang fallback, which initialized from the chip's unique ID and timer registers without collecting fresh entropy.
An attacker who can determine the device's unique identifier, its timer state and the history of prior random number generator calls can reproduce potential seed streams offline. Those candidate seeds can then be tested by deriving addresses and comparing them against public blockchain records.
Coinkite, the maker of Coldcard, estimates effective entropy for generated seeds at roughly 40 bits on its Mk3 model and around 72 bits on the Mk4, Mk5 and Q models. A secure 12-word BIP-39 seed requires 128 bits.
Coinkite pushed emergency firmware updates for all affected models and release tracks on July 31. That update does not retroactively secure seeds created with the vulnerable firmware. Owners must generate a new seed on a patched device and transfer their assets.
Restoring a compromised seed to updated firmware or any other wallet propagates the underlying vulnerability. Coinkite said a strong, unique BIP-39 passphrase adds a layer of protection but still recommends a full seed replacement.
Multisignature configurations offer protection only if the required quorum of signers does not rely entirely on devices with affected seeds. Coinkite's TAPSIGNER, OPENDIME and SATSCARD products use distinct codebases and are not affected by this vulnerability.
The attacker's identity remains unknown. Galaxy Research identified a consistent transaction signature across drained addresses—a 30 sat/vB fee with no change output. The firm found no other Bitcoin transactions matching that pattern in the 30 days before the July 30 exploit.

