Hacking

Coldcard Firmware Vulnerability Leads to $70M Bitcoin Theft

Published  ·  7 min read

Here is a nightmare scenario for anyone holding Bitcoin in a hardware wallet. An attacker drained 1,196 Bitcoin addresses in just 41 minutes on July 30, taking 1,082.65 BTC worth about $70.2 million at the time. The target was Coldcard, the Bitcoin-only hardware wallet made by Canadian firm Coinkite.

Galaxy Research mapped the sweep and tied it to a firmware flaw in the Coldcard devices. The vulnerability dates back to a March 2021 firmware integration error that routed seed generation to a deterministic software pseudorandom number generator instead of the hardware random number generator.

Let me walk through what happened, which devices are affected, and what Coldcard owners need to do right now.

The Coldcard Firmware Vulnerability Explained

The Coldcard firmware vulnerability is a seed generation flaw that traces back to a March 2021 integration error. Coinkite's production configuration defines MICROPY_HW_ENABLE_RNG as zero because the company supplies its own hardware-RNG wrapper. 

The libngu library checked whether the macro existed rather than whether it was enabled. This bound the build to MicroPython's Yasmarang fallback instead of the STM32 hardware random number generator.

The MicroPython fallback was initialized from the chip's unique ID and timer registers. It collected no fresh entropy after initialization. This means the random numbers used to generate wallet seeds were not truly random. They were deterministic and potentially predictable.

Block, the research firm that analyzed the Coldcard firmware vulnerability, says an attacker who can determine or sufficiently constrain the device UID, timer state, and prior RNG-call history can reproduce candidate output streams offline without accessing the device. 

Candidate seeds can then be checked by deriving their addresses and comparing them with public blockchain data.

The Attack in Action

The attack was swift and devastating. Galaxy Research mapped the sweep of 1,196 Bitcoin addresses in just 41 minutes. The attacker took 1,082.65 BTC worth approximately $70.2 million at the time of the theft.

Galaxy found no other Bitcoin transactions in the previous 30 days with the same 30 sat/vB fee rate and no-change signature. This pattern helped identify the operator of the sweep. 

However, Galaxy warned that the pattern identifies the operator, not the theft, because a sweep "looks the same as if a coin owner chose to move coins."

No one has publicly named the attacker. The investigation into who is behind the Coldcard firmware vulnerability exploitation is ongoing.

How Much Entropy Was Lost?

The Coldcard firmware vulnerability resulted in significantly reduced entropy for seed generation. Coinkite estimates the effective entropy at roughly:

  • 40 bits on the Mk3
  • About 72 bits on the Mk4, Mk5, and Q

This compares to 128 bits for a proper 12-word BIP-39 seed. A 40-bit entropy is trivial to brute force with modern hardware. Seventy-two bits is more difficult but still potentially achievable for a determined attacker with significant resources.

Block does not give one practical figure. It sets conditional ceilings below 240.7 and 273.3 and warns that the latter is not equivalent to 73-bit cryptographic security. The Coldcard firmware vulnerability created seeds that were far weaker than intended.

Which Coldcard Devices Are Affected?

Exposure depends on the firmware running when the seed was created, not the version installed now. This is a critical distinction. If you created your seed on a vulnerable version and later updated, your seed is still compromised.

The affected versions are:

  • Mk2 and Mk3: Coinkite lists Mk3 versions 4.0.1 through 4.1.9, fixed in 4.2.0. Block places both Mk2 and Mk3 versions 4.0.0 through 4.1.9 on the vulnerable path.
  • Mk4 and Mk5: Anything before 5.6.0
  • Q: Anything before 1.5.0Q
  • Edge builds: Before 6.6.0X for Mk4 and Mk5, before 6.6.0QX for Q

If you created your seed on any of these versions, your wallet is potentially at risk from the Coldcard firmware vulnerability.

What Does Not Protect You

The Coldcard firmware vulnerability requires careful consideration of what actually protects you. Coinkite says a seed built with at least 50 fair, independent, private dice rolls is not at risk from this bug alone. If the number or privacy of the rolls is uncertain, Coinkite says to migrate.

A strong, unique BIP-39 passphrase creates a separate wallet that the seed words cannot reach on their own. But the company still recommends replacing the seed entirely.

Multisig helps only when the quorum is not built entirely from affected devices. If all your multisig devices are vulnerable Coldcards, you are still at risk.

What Devices Are Not Affected?

Not all the products from Coinkite are affected by the Coldcard firmware vulnerability. TAPSIGNER, OPENDIME, and SATSCARD use different codebases and are unaffected. Only Coldcard devices running the vulnerable firmware versions are at risk.

Coinkite's Response

Coinkite shipped emergency firmware for every affected model and release track on July 31. But installing the new firmware does not repair an existing seed. The company tells owners with exposed seeds to generate a new one on patched firmware and move their coins.

Restoring the old seed to updated firmware or another wallet carries the weakness forward. If you restore a vulnerable seed, you are still at risk regardless of the firmware version. The only safe option is to generate a completely new seed on patched firmware and transfer your funds.

The Connection to Ill Bloom Research

The Coldcard firmware vulnerability disclosure follows Coinspect's Ill Bloom research in early July. That was a separate weak-PRNG flaw in older software wallets tied to more than $5 million drained from addresses across Bitcoin, Ethereum, Tron, Rootstock, and Polygon since May.

The timing of these two disclosures is coincidental but highlights a broader issue. Pseudorandom number generator flaws have been a recurring problem in cryptocurrency wallets. When random number generation fails, funds are at risk.

What Coldcard Owners Should Do

If you own a Coldcard, here is what you need to do:

  • Check which firmware version you used when you created your seed
  • If you used any affected version, your seed is potentially compromised
  • Update your Coldcard to the latest emergency firmware
  • Generate a completely new seed on the patched firmware
  • Transfer all funds from the old wallet to the new one
  • Do not restore your old seed on any device

This is not optional. The Coldcard firmware vulnerability has already been exploited to steal millions of dollars. Attackers are actively scanning for vulnerable seeds. Do not wait.

The Broader Implications

The Coldcard firmware vulnerability is a reminder that hardware wallets are not magic boxes. They are complex devices running software. Bugs can and do happen. When a bug affects seed generation, the consequences can be catastrophic.

Coldcard has a strong reputation in the Bitcoin community. This incident will do nothing to alter that reputation, but it will serve to illustrate the significance of firmware updates and proper seed generation. 

Wrapping It Up

The Coldcard firmware vulnerability enabled the attacker to drain 1,196 Bitcoin addresses in 41 minutes. This hack of $70.2 million is one of the biggest in hardware wallet history. The vulnerability results from an error made in March 2021 that has resulted in a reduction of seed entropy to as little as 40 bits.

Coinkite has released emergency firmware fixes, but patching alone does not protect existing seeds. Coldcard owners must generate new seeds on patched firmware and move their funds.

If you are a Coldcard user, do not delay. The attackers are already using this Coldcard firmware vulnerability. Your funds may be at risk. Update, migrate, and secure your Bitcoin.

FAQ Section

What is the Coldcard firmware vulnerability?

It is a seed generation flaw caused by a March 2021 integration error that routed seed generation to a deterministic software PRNG instead of the STM32 hardware RNG. This significantly reduced entropy and made seeds potentially predictable.

Which Coldcard devices are affected?

Affected versions include Mk2 and Mk3 versions 4.0.0 through 4.1.9, Mk4 and Mk5 before 5.6.0, Q before 1.5.0Q, and Edge builds before 6.6.0X for Mk4/Mk5 or 6.6.0QX for Q.

How much Bitcoin was stolen?

An attacker drained 1,196 addresses in 41 minutes, taking 1,082.65 BTC worth approximately $70.2 million at the time of the theft.

What should Coldcard owners do?

Update to the latest emergency firmware, generate a completely new seed on the patched firmware, and transfer all funds. Do not restore your old seed on any device.

Does a passphrase protect me?

A strong, unique BIP-39 passphrase creates a separate wallet, but Coinkite still recommends replacing the seed entirely as the safest option.

Source: The Hacker News
Professional Services

Explore Our Cybersecurity Services

Our insights are backed by hands-on service delivery. If your business needs professional cybersecurity support, our UK-based specialists are ready to help.

© 2016 – 2026 Red Secure Tech Ltd. Registered in England and Wales — Company No: 15581067