Coldcard Exploit Drains $70M in Bitcoin, CZ Warns Users
A firmware flaw in Coldcard hardware wallets allowed attackers to guess private keys, draining $70.2M in BTC from 1,196 addresses. CZ urged users to diversify wallets as Coinkite rushed emergency patches.
Quick Take
Coldcard firmware bug since March 2021 weakened seed entropy, enabling key guessing.
Galaxy Research identified 1,196 addresses drained for 1,082.65 BTC (~$70.2M) in 41 minutes.
CZ warns against blind trust in hardware wallets, advises splitting funds across wallets.
Stolen Bitcoin consolidated into few addresses and has not moved; users urged to migrate seeds.
Market Impact Analysis
BearishNegative security news could shake confidence in hardware wallets, but overall crypto market reaction is likely muted.
Speculation Analysis
Key Takeaways
- A firmware bug in Coldcard wallets since March 2021 weakened seed generation, allowing attackers to guess private keys and drain funds.
- Galaxy Research traced 1,082.65 BTC (~$70.2 million) stolen from 1,196 addresses within a 41-minute window on July 30.
- Binance founder CZ warned crypto users that no hardware wallet is foolproof, advising diversification across multiple wallets to mitigate single-point risks.
- Coinkite shipped emergency firmware fixes, but affected seeds remain compromised; users must migrate to new seeds to secure funds.
What Happened
A critical flaw in Coldcard hardware wallets led to the theft of over 1,082 Bitcoin, worth roughly $70.2 million. The vulnerability stemmed from a firmware build error dating back to March 2021 that caused affected devices to generate wallet seeds using a software fallback instead of the dedicated hardware random-number generator. This weakened the entropy, making private keys susceptible to guessing. On July 30, an attacker swept funds from 1,196 addresses within a tight 41-minute window. The stolen Bitcoin was consolidated into a handful of addresses and has remained static since. The incident triggered a swift response from manufacturer Coinkite and a public warning from Binance founder Changpeng Zhao.
The Numbers
Galaxy Research mapped the attack, revealing a loss of 1,082.65 BTC—approximately $70.2 million—drained from 1,196 addresses. The exploitation unfolded between 01:10:20 and 01:51:26 UTC on July 30, a narrow 41-minute sprint. Early estimates had pegged the damage at 594 BTC (about $38 million) across 500 wallets, but the full scope nearly doubled upon closer analysis. The consolidated stolen funds have not moved since the initial heist. The underlying firmware bug was introduced in a March 2021 build and remained undetected until the exploit.
Why It Happened
The root cause was a build error in Coldcard’s firmware shipped in March 2021. Instead of using the hardware’s true random-number generator to create seed phrases, the device relied on a predictable software fallback. This drastically reduced the pool of possible private keys, allowing attackers to reverse-engineer or brute-force them. Because the flaw existed in the seed generation process, simply updating the firmware does not fix already compromised seeds. Users who created their wallets with the affected firmware remain exposed until they migrate to a new seed generated on a patched device.
Broader Impact
The exploit underscores a critical reminder: hardware wallets, while more secure than software alternatives, are not infallible. CZ’s warning to avoid blind trust and diversify across multiple wallets reflects a growing sentiment that security requires layered strategies. The incident may prompt other hardware wallet manufacturers to audit their firmware more rigorously, potentially reshaping industry standards for seed generation and user guidance. Coldcard users, in particular, face a wake-up call about the importance of verifying their device’s firmware integrity.
What to Watch Next
- Whether the stolen 1,082 BTC moves or is laundered—any activity could signal further attack patterns or law enforcement involvement.
- Coinkite’s long-term response: beyond emergency patches, will they implement more robust safeguards to prevent similar build errors?
- Other hardware wallet makers may face increased scrutiny, potentially leading to new disclosure practices or security certifications for entropy generation.
This article is for informational purposes only and does not constitute financial advice.
Always late to trends?
Join for the latest news, insights & more.
Disclaimer: Bytewit is an independent media outlet that delivers news, research, and data.
© 2026 Bytewit. All Rights Reserved. This article is for informational purposes only.