Coldcard Firmware Flaw Drains $89M From 4,500 Bitcoin Wallets in 3 Waves
CMC Crypto News

Coldcard Firmware Flaw Drains $89M From 4,500 Bitcoin Wallets in 3 Waves

3m
1 hour ago

A March 2021 Coldcard firmware bug let attackers steal ~1,367 BTC worth $89M from 4,585 addresses across 3 waves. Galaxy Research warns all vulnerable wallets will be drained.

Coldcard Firmware Flaw Drains $89M From 4,500 Bitcoin Wallets in 3 Waves

Daftar Isi

Crypto Security News

A coding error in a March 2021 Coldcard firmware release has enabled attackers to steal approximately 1,367 Bitcoin (BTC), worth close to $89 million, from 4,585 addresses. Galaxy Research tracked the theft across three separate waves of attacks between July 30 and Aug. 2. The firm flagged the third and most recent wave early on Aug. 2, reporting that roughly 208 BTC was drained from 1,912 addresses between midday July 31 and the morning of Aug. 1 UTC.

The flaw exists in version 4.0.1 of the Coldcard Mk3 firmware. That build mistakenly routed seed phrase generation to a software-based random number generator rather than the dedicated hardware chip inside the device. A software randomizer produces a predictable, bounded range of outputs. Any attacker who knows the flaw can reconstruct the possible private keys offline and check each one against funded addresses, without ever handling a physical wallet.

Three Waves, One Flaw

The first wave hit on July 30, draining 1,082.65 BTC from 1,196 addresses in a 41-minute window between 1:10 and 1:51 am UTC. That wave averaged close to 1 BTC per victim. The second wave targeted mid-sized wallet balances. By the third wave, each victim lost an average of roughly 0.1 BTC. Galaxy’s head of research Alex Thorn attributed the declining haul to the attacker having already cleared the highest-value addresses from the vulnerable key space.

The third wave also changed its on-chain tactics. Earlier waves funneled victim funds into a small set of shared collector addresses, which made them easy to map. Wave three routed each victim's coins to a unique destination address instead. It also used pay-to-witness-script-hash (P2WSH) outputs, a format that can carry multisignature or timelock conditions, in place of the plain single-key outputs used before.

Additionally, it batched an average of six victims per sweep transaction, where wave one had processed one address at a time. Wave three also limited itself to the default key derivation path rather than scanning multiple branches per seed. Galaxy said it is confident each wave reflects a single internal operator but declined to formally link the three waves to each other. The stolen coins from all three waves have remained in attacker-controlled addresses and have not moved.

Related Article: Crypto Hack Losses Passed $1B in H1 2026, Blockaid Reports

Coinkite CEO Rodolfo Novak, known online as NVK, issued an apology on July 31. He said the company accepts full accountability for the firmware bug and acknowledged that its internal review process failed to catch the error. Novak suggested the vulnerability may have been uncovered through AI-assisted code analysis. He called the situation "a sober reality of the new AI paradigm" and noted that AI tools can surface dormant bugs in publicly available code faster than conventional security review. Coinkite expanded its advisory beyond the Mk3 to include certain Mk4, Mk5, and Coldcard Q firmware versions. It also released emergency firmware updates for all affected models. Galaxy said it has shared approximately 600 suspected attacker addresses with federal investigators, compliance firms, and cross-industry cybersecurity researchers.

Move Funds Now, Researchers Warn

Thorn posted on X on Aug. 2 that the attack is ongoing. He urged anyone with single-signature funds on Coldcard-generated addresses to move them immediately. He noted the stolen coins had sat dormant for an average of 3.18 years before being swept, indicating the victims were primarily long-term holders. The exploit has reversed a common self-custody practice for many affected users. Large numbers of them are moving BTC off hardware wallets and back onto centralized exchanges or freshly generated addresses.

For some, that response came too late. Canadian fitness coach Jonathan Goodman wrote on X that 18.25 BTC, worth approximately CA$1.6 million ($1.16 million), was swept from his wallets across a seven-minute window on July 29. His private keys had been stored in a physical safety deposit box and had never connected to the internet. "Perhaps the hardest part about this is that I did everything right," Goodman wrote. He added that he is filing reports with police and the Ontario Securities Commission.

This article contains links to third-party websites or other content for information purposes only (“Third-Party Sites”). The Third-Party Sites are not under the control of CoinMarketCap, and CoinMarketCap is not responsible for the content of any Third-Party Site, including without limitation any link contained in a Third-Party Site, or any changes or updates to a Third-Party Site. CoinMarketCap is providing these links to you only as a convenience, and the inclusion of any link does not imply endorsement, approval or recommendation by CoinMarketCap of the site or any association with its operators. This article is intended to be used and must be used for informational purposes only. It is important to do your own research and analysis before making any material decisions related to any of the products or services described. This article is not intended as, and shall not be construed as, financial advice. The views and opinions expressed in this article are the author’s [company’s] own and do not necessarily reflect those of CoinMarketCap.
0 people liked this article