Coldcard Wallet Attack Losses Top $130M as 15 Attackers Drain BTC

iconNS3
Share
AI summary iconSummary
BTC price dipped slightly amid a major security breach as Coldcard wallet losses topped $130 million, with 15 attackers draining BTC from 7,300 wallets. Galaxy Research and Coinkite linked the issue to faulty firmware in Mk2, Mk3, and Mk4 models that weakened seed entropy. Hotfixes are available, but prior seed generation remains vulnerable. The incident may affect BTC dominance as users reassess hardware wallet security.

Key Point

Galaxy Research concluded Tuesday morning that 15 separate attackers are draining BTC from Coldcard customers’ hardware wallets. Estimated victim losses have topped $130 million from 7,300 wallets, and Galaxy Research has heard from 73 victims as of Monday. The fifteenth attacker surfaced overnight after one owner reported losing less than a single BTC, and Galaxy Research linked that footprint to 12 BTC pulled from 126 wallet addresses. Coinkite said faulty firmware routed seed generation into MicroPython’s software fallback, leaving Coldcard Mk2 and Mk3 seed phrases at about 40 bits of entropy and Coldcard Mk4 at about 72 bits. Coinkite has shipped hotfixes for affected models, but Coinkite warned that the threat is still active and that firmware updates do not repair seeds generated by affected firmware.

Why it matters: Weak seed generation can turn a public-address search into an ongoing custody risk, so losses may continue until vulnerable funds move to safer wallets.

Market Sentiment

Bearish, Stress-on, Event-driven, De-risking.

Reason: Estimated victim losses have topped $130 million, so traders may treat the incident as an active custody stress event.

Similar Past Cases

In 2023, Atomic Wallet users sued over more than $100 million in crypto lost to a wallet hack, which showed how wallet compromise events can create large user losses and prolonged recovery disputes. (Bloomberg Law) The difference is that the Coldcard case centers on weak seed generation in affected hardware-wallet firmware.

Ripple Effect

Weak seed generation can spread risk beyond one theft wave because attackers can scan public addresses and race owners to move funds. If vulnerable owners rotate funds to fresh seeds, then the active attack surface may shrink. If stolen coins begin moving from dormant wallets, then market stress may shift from custody risk to potential liquidation risk.

Opportunities & Risks

Opportunities: If Coinkite or Galaxy Research identifies more attacker footprints, then moving funds away from affected seeds is a direct custody-risk reduction signal.

Risks: If affected owners delay moving BTC to fresh wallets, then attackers can keep draining vulnerable addresses and custody risk remains active.

Disclaimer: The information on this page may have been obtained from third parties and does not necessarily reflect the views or opinions of KuCoin. This content is provided for general informational purposes only, without any representation or warranty of any kind, nor shall it be construed as financial or investment advice. KuCoin shall not be liable for any errors or omissions, or for any outcomes resulting from the use of this information. Investments in digital assets can be risky. Please carefully evaluate the risks of a product and your risk tolerance based on your own financial circumstances. For more information, please refer to our Terms of Use and Risk Disclosure.