Coldcard bitcoin wallet flaw drains 594 BTC in 25-minute sweep

A bitcoin wallet flaw in Coldcard hardware wallets enabled an attacker to drain about 594 BTC worth roughly $38 million from around 500 single-signature wallets in under 30 minutes. On-chain activity showed 1,324 BTC “chunks” moved across 500 transactions within a three-block window (01:31–01:56 UTC). A large portion (562 BTC) was then consolidated into a single address that has not moved. The issue traces to Coldcard firmware 4.0.0, introduced in March 2021. The bug made the device skip its hardware randomness generator and fall back to predictable software key generation. The software seed relied on nonsecret device data (chip serial and clock registers), which attackers could narrow down or measure. Exposure depends on the firmware used when the wallet seed was first created, not the purchase date. Coinkite warned users who generated seeds on Mk3 devices running firmware 4.0.1 or later, while stating Mk4, Q, and Mk5 appear unaffected based on early analysis. Block’s Bitcoin engineering and security teams reported the finding to Coinkite and published without full exploitability testing because theft was already underway. The same flawed generator also impacted other Coldcard key material types, including paper wallet private keys and certain cloning/transfer-related keys. Despite the scale, the article says the theft had little visible impact on bitcoin’s price; BTC traded above ~$64,000 in early Asian hours.
Neutral
The news is a major security incident, but the article explicitly notes limited visible impact on bitcoin’s market price. In similar past wallet-related events, markets often react more to broader risk appetite and macro/ETF flows than to the exact exploited wallet count—unless the incident escalates into a systemic breach that shakes confidence across many custodians. Here, the exploit appears firmware- and seed-creation dependent (affected by specific Coldcard firmware/seed generation conditions). That containment by version scope usually keeps the market reaction muted: traders may see short-term headlines-driven volatility, but liquidity and positioning often stabilize once exploitability and affected cohorts are clarified. Short-term (days): potential for volatility around “wallet exploit” narratives, plus cautious behavior from self-custody users. Long-term (weeks+): if verification confirms that only certain Coldcard models/firmware are impacted, broader BTC price effects are likely limited; however, it can tighten risk controls (wallet migration, firmware upgrades) and increase monitoring, which can influence sentiment toward hardware wallet providers. Given the reported “little visible impact” and the targeted nature of the affected firmware cohort, the overall trading implication is best categorized as neutral.