Coldcard firmware flaw leads to $130M in stolen Bitcoin
A Coldcard firmware bug allowed remote key reconstruction, resulting in at least 1,596 BTC stolen from about 7,300 addresses and prompting mass wallet migrations and exchange deposits.
Galaxy Research reported that attackers used a Coldcard hardware wallet firmware flaw to steal at least 1,596 BTC from roughly 7,300 addresses. The firm identified three major attack waves and 14 smaller incidents, and it flagged a possible fourth wave that could raise losses to about 2,055 BTC (roughly $130 million) pending additional victim reports. Researchers identified as many as 15 separate attackers and say about 73 victims contacted Alex Thorn, head of research at Galaxy, for help tracing funds. Approximately 90% of the stolen coins remain at attacker-controlled addresses. Galaxy shared the addresses with U.S. law enforcement, cryptocurrency exchanges and blockchain investigators to help flag the funds if they move through centralized platforms.
The vulnerability dates to March 2021. A coding error caused some Coldcard devices to generate recovery seeds using a weaker software process instead of drawing sufficient randomness from the device’s hardware random-number generator. That produced recovery phrases with far fewer possible combinations than intended, enabling remote reconstruction of private keys without physical access to the device or the owner’s recovery words. Coinkite, the manufacturer of Coldcard, released a firmware update that stops the creation of additional weak seeds but cannot secure wallets whose recovery phrases were generated under the flawed process. Coinkite has urged users to install the update, create a new recovery phrase and transfer funds to addresses derived from the new phrase.
The exploit triggered a surge in Bitcoin network activity as affected users moved coins. One analytics firm recorded about 712,000 active Bitcoin addresses over seven days and 61,800 transactions larger than $100,000. Another analytics provider reported transactions below $100,000 totaling $3.2 billion, the highest since November 2024, and said spending by long-term holders outside exchanges rose to 406,000 BTC on a 30-day basis as of Aug. 3, up from 269,000 BTC before the exploit. The rush of migrations also increased network congestion: the Bitcoin mempool grew from about 33,000 pending transactions to roughly 96,000.
Some migrated coins were moved into centralized exchanges. Exchange reserves rose by roughly 17,500 BTC between July 28 and Aug. 3, climbing from about 2.702 million BTC to 2.719 million BTC. One major exchange received roughly 9,000 BTC of that net increase, about 51% of the total, bringing its reserves to about 659,000 BTC. Deposits from smaller holders reached their highest levels since early February, consistent with users seeking temporary custodial options while arranging secure migrations.
Phishing and social-engineering attempts increased after the flaw became known. A competing hardware wallet maker warned customers not to share recovery phrases or enter them into websites, applications or unsolicited forms and confirmed its devices were not affected. Security guidance notes that importing a weak seed into another device does not remove the vulnerability; users must generate a new recovery phrase and transfer funds to addresses derived from it. Until affected users move funds to addresses generated from secure seeds, those wallets remain exposed and risk persists.








