Attacker Drains $116M in Bitcoin From Coldcard Addresses

iconNS3
Share
AI summary iconSummary
Bitcoin breaking news: An attacker drained 1,816 Bitcoin, worth $116 million, from over 5,200 Coldcard wallet addresses since July 30. Galaxy Research reported the largest single sweep involved 1,082 Bitcoin from 1,196 wallets in 41 minutes. The flaw originated from a firmware setting in Coldcard version 4.0.0 that skipped the hardware randomness chip. Coinkite CEO Rodolfo Novak urged users to migrate funds using updated best practices. Users who generated seeds with at least 50 private dice rolls or used a strong passphrase were unaffected. Bitcoin news outlets are closely tracking the incident.

Key Point

An attacker moved about 1,816 bitcoin, roughly $116 million, from more than 5,200 addresses generated on Coldcard devices since July 30. Galaxy Research counted the largest sweep at 1,082 bitcoin from 1,196 wallets inside 41 minutes. Coldcard firmware version 4.0.0, shipped in March 2021, carried a build setting that told the device to skip its dedicated hardware randomness chip. Coinkite chief executive Rodolfo Novak urged users who generated seeds with Coldcard wallets to migrate funds using updated best practices. Owners who generated seeds with at least 50 private dice rolls, or who used a strong passphrase, were unaffected.

Why it matters: A wallet entropy failure can turn offline self-custody into hidden key exposure and may weaken trust in hardware wallet security.

Market Sentiment

Cautiously Bearish, Stress-on, Tech-driven, De-risking.

Reason: The reported drain from Coldcard-generated addresses may weaken confidence in self-custody hardware security.

Similar Past Cases

Trust Wallet fixed a WebAssembly vulnerability in its browser extension after the issue led to $170,000 in user losses, according to The Block. The case showed how weak seed generation can leave wallets exposed even without phishing or device theft. (The Block) The key difference is that the Trust Wallet case involved browser extension software, while the current event involves Coldcard hardware wallet seed generation.

Ripple Effect

Entropy doubts can push users away from single-device custody and toward systems with more operational controls. Custody demand may rise if large holders decide that hardware isolation alone does not control hidden implementation risk. If Coinkite publishes its technical review and migration guidance, then containment may depend on whether users rotate vulnerable seeds quickly.

Opportunities & Risks

Opportunities: When Coinkite publishes the technical review, then a clear fault boundary can become a potential confidence-repair signal for hardware wallet users. If migration guidance proves narrow, then self-custody providers with stronger entropy controls may gain user trust.

Risks: If additional waves empty Coldcard-generated addresses, then reducing single-device exposure can limit operational downside. If the technical review shows broader seed-generation exposure, then custody risk may remain elevated across affected users.

Disclaimer: The information on this page may have been obtained from third parties and does not necessarily reflect the views or opinions of KuCoin. This content is provided for general informational purposes only, without any representation or warranty of any kind, nor shall it be construed as financial or investment advice. KuCoin shall not be liable for any errors or omissions, or for any outcomes resulting from the use of this information. Investments in digital assets can be risky. Please carefully evaluate the risks of a product and your risk tolerance based on your own financial circumstances. For more information, please refer to our Terms of Use and Risk Disclosure.