A Bitcoin hardware wallet that was supposed to be unhackable just had its worst nightmare come true: up to USD 89 million drained from thousands of wallets in 41 minutes.
The victim is the COLDCARD, a favorite of serious Bitcoin self-custody users, made by Canadian company Coinkite. Researchers at Galaxy Research tracked the attack, which began on July 30 and is still being investigated.
Here is what happened, which wallets are at risk, and what you should do right now if you own one.
The attack in numbers
Galaxy Research’s initial tracking found 1,082.65 Bitcoin, worth about USD 70 million, drained from 1,196 wallet addresses in a 41 minute window. The funds moved to four attacker controlled addresses in what researchers called likely automated activity.
Galaxy then identified two additional waves of suspicious activity on August 1, pushing the total to roughly 1,367 Bitcoin, or about USD 89 million.
This is one of the largest hardware wallet heists in Bitcoin history, and it happened to devices that were specifically marketed as the secure way to hold coins offline.
The root cause: a five year old RNG bug
The vulnerability is not in a web app or an exchange, it is inside the wallet firmware itself. Block’s Bitcoin Engineering and Security team traced the incident to a firmware vulnerability dating back to 2021.
Due to the bug, the wallet sometimes did not use its hardware based random number generator when creating wallet seeds, the master keys that control your coins. Instead it used a fallback generator that was deterministic, meaning an attacker could predict the seeds.
Worse, the flaw involved a 32 bit reseed, which dramatically reduced the randomness of generated keys. In plain language: some COLDCARD users’ private keys were much weaker than they thought, and an attacker figured out how to find them.
Which COLDCARDs are affected
Coinkite has published a detailed security advisory on its official blog, and the news is mixed depending on your model.
Mk2 and Mk3 units running firmware versions 4.0.1 (March 2021) through 4.1.9 inclusive are the most exposed. Seeds generated on those versions are at risk unless they were created with at least 50 fair, independent, private dice rolls.
Mk4, Mk5, and Q wallets are also affected, but less severely. Seeds generated on them before the fixed firmware have about 72 bits of entropy instead of the expected 128 bits, which is still weak enough to be dangerous.
Good news for some: TAPSIGNER, OPENDIME, and SATSCARD use different codebases and are not affected by this bug.
What Coinkite says to do
Coinkite’s first line of advice is blunt: do not generate a new seed on any affected model until you install the fixed firmware. Updating the firmware does not repair an existing seed, it only makes new seeds safe.
Fixed firmware is out for every affected model: Mk2 and Mk3 get version 4.2.0 or later, Mk4 and Mk5 standard get 5.6.0 or later, Q standard gets 1.5.0Q or later, and Edge tracks get 6.6.0X or later.
If you generated a seed on affected firmware, Coinkite wants you to migrate to a newly generated seed on updated firmware. The advisory includes a careful step by step process: verify your backup, update firmware, generate a new seed, test with a small transaction, then move the rest.
A strong, unique BIP-39 passphrase adds an independent barrier and reduces immediate exposure, but it does not repair the affected seed. Coinkite says passphrase users should still migrate as soon as practical.
The one thing that protects you
There is an exception baked into the advisory: if you created your seed with at least 50 fair, independent, private dice rolls, the dice input alone contributed at least 128 bits of entropy, and your seed is not at risk from this RNG issue.
That is the COLDCARD’s famous dice roll method working exactly as designed, and it is the difference between safe and exposed for thousands of users.
Fewer than 50 rolls, rolls you do not remember, or rolls that were not private? Treat the seed as at risk and migrate.
What this means for crypto users
This attack is a brutal reminder that hardware wallets are not magic. They protect you from online attacks, but a firmware bug in the random number generator defeats the entire premise of offline security.
Galaxy Research has cautioned that the attacks may still be happening, and researchers are continuing to study exactly how the vulnerability is being exploited.
If you hold Bitcoin in a COLDCARD, especially an Mk2 or Mk3, check your firmware version today. If you are on an affected build, follow Coinkite’s migration guidance, carefully, before doing anything else.
Your wallet was supposed to be the fortress. Make sure yours is not one of the ones with a back door.
