Coldcard wallet flaw: 1,082 BTC stolen before security warning
A Coldcard wallet flaw has led to one of the largest recent Bitcoin hardware wallet thefts. Galaxy Research reports an attacker drained 1,196 vulnerable Coldcard Bitcoin wallet addresses in a 41-minute window on July 30 (01:10–01:51 UTC), stealing about 1,082.65 BTC (≈$70.2M). The withdrawals occurred almost 30 hours before Coinkite, Coldcard’s maker, issued a public security warning.
The issue stems from a 2021 firmware update that inadvertently reduced the entropy used to generate recovery seed phrases on affected devices. Instead of secure hardware randomness, some wallets relied on a software-based random number generator using predictable inputs (e.g., device serial number and internal clock). Researchers estimate seed security dropped from the expected 128-bit entropy to about 40 bits on certain Mk3 firmware versions (4.0.1–5.0.3), enabling offline private-key recreation and automated draining.
Researchers also note transaction patterns: a consistently high 30 sat/vB fee and no change output, suggesting the attacker already held the private keys. Investigators identified remaining consolidated holdings, including an address with over 562 BTC and others with 398 BTC, 89 BTC, and 32 BTC that did not move after consolidation.
Coinkite advises users who generated recovery phrases on affected firmware to immediately move funds to a newly created wallet using the latest firmware. Users with an additional BIP-39 passphrase face lower risk because it adds a second security layer. Analysts warn more vulnerable Coldcard wallets may still be exposed if owners delay migration.
Coldcard wallet flaw is now the key market risk theme for BTC hardware-wallet users: security upgrades and migration decisions may drive short-term sentiment swings around custody reliability.
Bearish
This news is bearish for sentiment around custody and hardware wallet reliability. Even though the stolen amount (≈1,082 BTC) is not large enough to threaten overall Bitcoin liquidity, a confirmed hardware-wallet firmware flaw and offline private-key recreation risk can trigger short-term panic selling from risk-averse traders. Historically, large “wallet compromise” headlines (e.g., major exchange or custody incidents) often cause brief volatility spikes as traders reassess operational risk.
In the short term, expect increased attention to Coldcard owners and hardware-wallet holders: migration activity and heightened security discussions can lead to localized sell pressure or higher demand for safer custody setups. In the long term, if Coinkite and researchers effectively reduce exposure through firmware fixes and user guidance, the impact may fade. However, the possibility that additional vulnerable wallets remain exposed can keep a persistent overhang on risk perception, influencing how traders price “self-custody safety” and prompting more conservative positioning.