Coldcard Bitcoin Hack Losses Near $114 Million as Attacks Exploit Firmware
A firmware flaw in Coldcard hardware wallets enabled attackers to systematically drain Bitcoin from air-gapped wallets, with losses surpassing $89 million and potentially reaching $114 million. The weak seed generation vulnerability from a March 2021 update compromised private keys. Galaxy Research tracked 1,367 BTC stolen and warned every vulnerable device will eventually be emptied.
Quick Take
Coldcard firmware flaw collapses seed security to 40 bits, making keys guessable.
Attackers drained 1,367 BTC, losses hit $89M and threaten to reach $114M.
Galaxy Research handed 600 suspect addresses to federal investigators.
Defenders may front-run transactions to save remaining funds.
Market Impact Analysis
BearishMassive theft erodes trust in hardware wallets and self-custody, potentially triggering sell pressure from user panic and liquidated stolen coins.
Speculation Analysis
Key Takeaways
- A Coldcard firmware bug reduced seed entropy to just 40 bits — allowing attackers to brute-force private keys without physical access.
- Over $89 million in Bitcoin has been siphoned from 4,585 wallets, with total losses poised to hit $114 million as a fourth attack wave begins.
- Galaxy Research identified three attack waves, passed 600 suspect addresses to federal investigators, and warns every vulnerable device will be drained.
- Defenders are racing to front-run transactions in the mempool to save remaining funds, but the exploit remains active.
What Happened
A critical firmware vulnerability in Coldcard hardware wallets has sparked one of the largest self-custody thefts in Bitcoin history. Attackers exploited a weak random number generator introduced in a March 2021 update, collapsing seed security from 128 bits to roughly 40 bits. This allowed them to guess private keys and drain wallets — even those kept in cold storage with no internet connection. The theft, first reported last week, quickly escalated over the weekend. Galaxy Research now tracks 1,367 BTC stolen across 4,585 addresses, and flagged a fourth attack wave on Saturday. The exploit remains ongoing, and every vulnerable device is expected to be emptied unless immediate countermeasures are taken.
The Numbers
Losses already exceed $89 million and could reach $114 million as new attacks hit. The thief has swept 1,367 BTC from 4,585 unique addresses in three distinct waves, with a fourth just beginning. Galaxy Research handed approximately 600 suspected attacker addresses to federal investigators. The bug originated from a firmware update that inadvertently used a software fallback for seed generation, weakening it drastically.
Why It Happened
The March 2021 Coldcard firmware update contained a critical flaw: it drew wallet seeds from a weak software-based random number generator instead of the hardware security module. That collapsed the effective key space from 128 bits to about 40 bits — making brute-force attacks trivial. Because Coldcard’s code is open-source, attackers likely used AI to scan the firmware and identify the vulnerability. Coinkite, the maker of Coldcard, admitted its own AI review weeks earlier failed to spot the bug. Galaxy’s head of research said the sweeps appear programmatic, likely orchestrated with a large language model. In essence, AI helped attackers crack a security model once considered bulletproof.
Broader Impact
This breach punctures trust in hardware wallets — long considered the gold standard for self-custody. If an air-gapped device can be drained remotely due to a firmware bug, the entire security paradigm faces doubt. The use of AI to locate and exploit the flaw also signals a dangerous new frontier, where machine learning accelerates vulnerability discovery and attack execution. Regulatory scrutiny over wallet security standards may intensify, and users may rethink cold storage strategies.
What to Watch Next
- Whether defenders can successfully front-run transactions in the mempool to rescue some funds before attackers finalize them.
- Developments from federal investigators as they analyze the 600 suspect addresses handed over by Galaxy Research.
- Potential firmware updates or hardware revisions from Coldcard, and how the market prices the reputational damage to hardware wallet providers.
This article is for informational purposes only and does not constitute financial advice.
Always late to trends?
Join for the latest news, insights & more.
Disclaimer: Bytewit is an independent media outlet that delivers news, research, and data.
© 2026 Bytewit. All Rights Reserved. This article is for informational purposes only.