Coldcard wallet exploit tops $116 million as fourth theft wave continues
Security & Exploits ·
A firmware bug from 2021 has left Coldcard hardware wallets exposed to predictable seed generation, and attackers are still draining funds four days into the incident.
The stolen total has climbed to roughly 1,816 BTC, valued near $116 million, pulled from more than 5,200 separate addresses in four distinct attack waves, according to news.bitcoin.com. The company behind Coldcard, Coinkite, has described the past several days as among the most difficult in its history and is urging affected users to move their holdings without delay.
The underlying issue dates back to a March 2021 firmware update that replaced a hardware-based randomness source with a software method that turned out to be guessable rather than resistant to brute force. Because any wallet seed generated under that flawed firmware could theoretically be predicted, the exposure has effectively existed for more than five years before this month's exploitation began.
Data cited through August 4–5 shows a sharp jump in on-chain activity tied to the incident, with CryptoQuant recording daily active Bitcoin addresses rising from about 645,000 to nearly 1 million as holders scrambled to shift funds out of vulnerable wallets. The pattern of repeated, organized waves — four in the span of days — suggests multiple actors may be independently working through the same predictable key space rather than a single party expanding one operation.
The scale of the migration raises the possibility that panicked transfers could add short-term liquidity pressure if a meaningful share of moved coins ends up on exchanges, though the material available does not indicate whether that has occurred. Separately, wublockchain.xyz is tracking coverage of the same cluster of events.
What remains unclear is whether additional waves will follow, how many affected addresses have yet to be swept, and what final loss figure the incident will settle at once tracing efforts catch up with the ongoing transfers. Coinkite's guidance to move funds immediately signals the vulnerability is still considered live, with no confirmation yet that the exposed key space has been fully mapped or contained.