Coldcard Firmware Flaw Leads to $88.6M Bitcoin Theft from 4,585 Addresses

iconUnLock
Share
AI summary iconSummary
Bitcoin news broke as a Coldcard firmware flaw from March 2021 led to the theft of 1,367 BTC (~$88.6M) from 4,585 addresses. Galaxy Research warns the attack is ongoing and urges users to move funds. The flaw weakened seed phrase entropy, allowing private keys to be predicted and exploited. BTC update activity shows a rise in small transfers, likely as holders move to centralized exchanges.

Summary

A firmware flaw in a March 2021 Coldcard update has enabled attackers to drain approximately 1,367 BTC (~$88.6M) from 4,585 addresses, with Galaxy Research warning the attack remains active and urging immediate fund migration.

Key Takeaways

  • The root cause is a March 2021 Coldcard firmware flaw that reduced entropy in seed phrase generation, making private keys for single-signature wallets predictable and systematically exploitable.
  • Galaxy Research warns every single-signature wallet created with the flawed firmware remains at risk; users should migrate funds to wallets generated with verified software immediately.
  • The exploit triggered the highest daily Bitcoin transaction volume under 1 BTC since November 2022, reflecting a temporary shift away from self-custody toward centralized exchanges among smaller holders.
  • At least one victim, Jonathan Goodman, lost 18.25 BTC despite following recommended offline storage practices, demonstrating that physical security measures cannot compensate for cryptographic key generation vulnerabilities.

A large-scale security exploit targeting Coldcard hardware wallets has resulted in the theft of nearly 1,367 Bitcoin, worth approximately $88.6 million, according to researchers at Galaxy Research, who say the attack remains active and could impact additional users.

The latest findings indicate that attackers have already drained funds from 4,585 Bitcoin addresses, with a third wave of thefts pushing total observed losses close to the $90 million mark.

Researchers are urging anyone using potentially affected Coldcard-generated wallets to transfer their assets immediately.

Third Wave Pushes Losses Higher

Galaxy Research reported that an additional 207.73 BTC was stolen during the latest wave of attacks, bringing total estimated losses to approximately 1,367 BTC.

According to Alex Thorn, Galaxy Digital's Head of Firmwide Research, investigators continue to identify both victim and attacker addresses as the exploit unfolds.

"The attack is ongoing," Thorn said in a post on X, advising users to move funds from vulnerable Coldcard-generated addresses without delay.

Galaxy said it has shared hundreds of suspected attacker wallet addresses with law enforcement agencies, compliance providers, and cybersecurity investigators to support ongoing efforts to trace the stolen assets.

Firmware Flaw Linked to Wallet Seed Generation

The exploit has been linked to a flaw introduced in a March 2021 Coldcard firmware update, which reportedly weakened the randomness used during seed phrase generation.

According to researchers, the issue affected the creation of private keys for certain single-signature wallets, making them significantly easier for attackers to predict than intended.

Galaxy believes the thefts were highly automated and coordinated, with Thorn suggesting the attackers may have used advanced automation tools to systematically identify and empty vulnerable wallets.

He also warned that every affected single-signature wallet generated using the flawed firmware could eventually be compromised if funds remain in those addresses.

Long-Term Bitcoin Holders Among the Victims

Researchers noted that many of the stolen Bitcoin had remained untouched for years before being drained.

Galaxy estimates the compromised funds had been dormant for an average of 3.18 years, indicating that many victims were long-term Bitcoin holders who believed their assets were securely stored offline.

At the time of publication, investigators said the stolen funds remained in attacker-controlled wallets and had not yet been moved further.

Self-Custody Confidence Shaken

The exploit has prompted an unusual response across the Bitcoin community, with some affected users temporarily abandoning self-custody in favor of centralized exchanges or newly generated wallets.

On-chain data shared by CryptoQuant Head of Research Julio Moreno showed that Bitcoin transfers below 1 BTC surged on Friday, with approximately 39,600 BTC moved in a single day.

The figure represents the highest daily volume for transactions under one Bitcoin since November 2022, shortly after the collapse of cryptocurrency exchange FTX, suggesting a wave of smaller holders relocating their assets following news of the exploit.

The migration marks a rare reversal of Bitcoin's long-standing "not your keys, not your coins" philosophy, as security concerns temporarily outweighed the preference for self-custody.

Victims Say They Followed Best Practices

Among those affected was Canadian entrepreneur and coach Jonathan Goodman, who said 18.25 BTC was stolen from his wallets within minutes despite storing his recovery phrase offline in a safety deposit box.

Goodman wrote that he had followed recommended security practices and is now reporting the incident to both law enforcement authorities and Canadian regulators.

The incident has renewed debate over hardware wallet security and the importance of verifying firmware integrity, while highlighting that even offline storage solutions remain vulnerable if cryptographic key generation is compromised.

With the ongoing investigation, security researchers are advising all users who may have created Coldcard single-signature wallets using the affected firmware to immediately transfer their Bitcoin to newly generated wallets created with verified software.

Disclaimer: The information on this page may have been obtained from third parties and does not necessarily reflect the views or opinions of KuCoin. This content is provided for general informational purposes only, without any representation or warranty of any kind, nor shall it be construed as financial or investment advice. KuCoin shall not be liable for any errors or omissions, or for any outcomes resulting from the use of this information. Investments in digital assets can be risky. Please carefully evaluate the risks of a product and your risk tolerance based on your own financial circumstances. For more information, please refer to our Terms of Use and Risk Disclosure.