Coldcard wallet exploit drains $88.6 million from thousands of Bitcoin addresses
Security & Exploits ยท
A firmware defect dating to 2021 has left thousands of Coldcard hardware wallets vulnerable to systematic draining, with losses now estimated at $88.6 million and climbing.
Researchers tracking the breach say attackers have pulled 1,367+ BTC from more than 4,500 addresses in a sequence of waves, according to Decrypt. The root cause traces to a March 2021 firmware build on Coinkite's devices, which substituted a software-based pseudo-random number generator for a hardware one, weakening the randomness used to create private keys and making them guessable. Coinkite has since released an emergency patch, but it only shields wallets generated after the fix โ funds already sitting in addresses created under the flawed firmware remain exposed, and some users have reported devices becoming unusable after applying the update.
The mechanics of the attack appear methodical rather than opportunistic. Analysts have described the sweeps as deliberate and programmatic, consistent with automated or AI-assisted coordination, and have warned that any single-signature Coldcard address generated after the 2021 update is likely to eventually be emptied. The scale of the problem has prompted a notable behavioral shift: holders are moving funds off self-custody and back onto centralized exchanges or freshly generated wallets, reversing the standard self-custody preference within the Bitcoin community.
Despite the size of the theft, immediate market impact looks limited. The bulk of the stolen Bitcoin has stayed parked in attacker-controlled addresses rather than being moved or sold, meaning direct sell-pressure on exchanges has so far been muted. That dormancy pattern has drawn attention because much of the compromised Bitcoin had reportedly sat untouched for years before being swept, suggesting long-term holders rather than active traders were among those affected.
The episode has also become a broader case study in the limits of hardware-wallet security assumptions. A separate analysis examined by The Block frames the exploit as evidence that Bitcoin's "don't trust, verify" ethos faces new strain as automated tools accelerate both attacks and defensive responses in wallet security.
What remains unresolved is the full scope of exposure: estimates of potential losses have varied across reporting, with some figures cited well above the $88.6 million confirmed tally, and a possible fourth wave of compromises has been flagged. It is also unclear how many vulnerable addresses have yet to be targeted, or whether affected users will recover any of the stolen funds through law enforcement or exchange cooperation.