Coldcard Seed Phrase Exploit Drains $38M BTC From 500 Dormant Wallets

iconNS3
Share
AI summary iconSummary
A BTC update reveals a seed phrase exploit impacted Coldcard hardware wallets, draining nearly 600 BTC—$38 million—from 500 dormant wallets. The attack moved funds from 500 single-signature addresses to one address in 25 minutes. Coinkite noted potential randomness issues in seed generation for Mk3 and pre-2021 Mk4 devices. Coldcard said Mk3 was at risk, but newer models were not. Block found a similar flaw in newer devices, linking it to a compile-time error. The incident highlights vulnerabilities in hardware wallets amid ongoing DeFi exploit concerns.

Key Point

A seed phrase exploit targeting Coldcard hardware wallets drained almost 600 BTC, worth $38 million, from roughly 500 dormant wallets yesterday. The attack moved BTC from 500 single-signature addresses into one address in 25 minutes, and reports suggest the exploit will likely continue. Coinkite confirmed that seed generation in its Mk3 wallet and updated versions beyond March 2021 version 4.0.1 may not have been random at all. Coldcard initially said Mk3 devices were at risk and Mk4, Q, and Mk5 were not affected based on early analysis. Block traced the bug to a mis-written compile-time check and found a smaller, real version of the same flaw in newer devices.

Why it matters: Hardware wallet exploits can weaken self-custody confidence and may push users to move funds if vulnerability scope remains uncertain.

Market Sentiment

Bearish, Stress-on, Event-driven, De-risking.

Reason: The $38 million BTC theft from dormant Coldcard wallets may weaken confidence in self-custody security.

Similar Past Cases

In 2022, Solana ecosystem teams traced a wallet-draining incident to Slope, and almost 8,000 wallets had been affected. Slope recommended that users create new seed phrase wallets and transfer assets to them. (The Block) The difference is that the Slope case involved software wallet exposure, while the Coldcard case centers on hardware wallet seed generation.

Ripple Effect

The direct channel is self-custody trust, because weak seed generation can turn dormant wallets into active loss risk. If reports of continuing exploitation prove correct, then affected users may rush to migrate funds and custody tools may face higher scrutiny. If newer devices remain within the vulnerability scope, then the security concern may spread beyond Mk3 users.

Opportunities & Risks

Opportunities: If Coinkite or Block narrows the affected firmware set, then moving funds only from devices inside that scope limits operational risk. If exploit activity stops after remediation details are published, then confidence in unaffected devices may stabilize.

Risks: If additional drains appear from the same vulnerability, then reducing reliance on affected hardware wallets becomes a practical risk-control signal. If newer devices remain inside the flaw scope, then delaying seed rotation leaves wallets exposed to continued compromise.

Disclaimer: The information on this page may have been obtained from third parties and does not necessarily reflect the views or opinions of KuCoin. This content is provided for general informational purposes only, without any representation or warranty of any kind, nor shall it be construed as financial or investment advice. KuCoin shall not be liable for any errors or omissions, or for any outcomes resulting from the use of this information. Investments in digital assets can be risky. Please carefully evaluate the risks of a product and your risk tolerance based on your own financial circumstances. For more information, please refer to our Terms of Use and Risk Disclosure.