A firmware vulnerability in Coldcard hardware wallets has enabled attackers to drain more than $88 million in Bitcoin from over 1,100 addresses in a single 41-minute window. The exploit, which occurred on July 30, initially netted $70 million before losses climbed, exposing a fundamental weakness in how the device creates its recovery seeds.

What You Need to Know

The attack targeted Coldcard wallets, which are marketed as high-security offline devices for storing Bitcoin. The flaw lies in the random number generator used to produce the wallet seed, making it predictable. An estimated 1,196 addresses were compromised, and the stolen funds now total 1,082.65 BTC. This incident undermines the core promise of hardware wallets: that private keys never leave the device.

The Vulnerability Explained

The security breach did not stem from a phishing scheme or a compromised online service. Instead, it originated from a flaw in Coldcard's firmware that governs how the wallet generates its seed phrase. The seed phrase is the cryptographic root from which all private keys are derived. If the seed generation process lacks true randomness, an attacker can reproduce the same seed and access the associated funds.

In this case, the attacker exploited a weakness in the random number generation algorithm, systematically deriving private keys for thousands of Coldcard wallets. The attack unfolded rapidly, draining addresses in batches over 41 minutes. The initial haul of $70 million grew to $88 million as additional compromised wallets were discovered.

Impact on Coldcard Users

Coldcard has long positioned itself as a premium choice for Bitcoin holders who demand maximum security. The device's air-gapped design and open-source firmware attracted advanced users and institutional custodians. This incident, however, calls into question the entire security model.

  • Coldcard users: Those who generated their seed using the compromised firmware version may have lost all funds. The attack is not limited to new wallets; older seeds created under the same flawed algorithm are also at risk.
  • Bitcoin network: While the exploit targets a specific device, it highlights a broader risk in hardware wallet design. Any wallet that relies on weak randomness for seed generation could face similar attacks.
  • Coldcard itself: The company faces a credibility crisis. Restoring user trust will require a transparent postmortem, a firmware fix, and possibly compensation for victims.

Why This Matters

This attack strikes at the foundation of self-custody in cryptocurrency. Users who follow best practices store private keys on hardware wallets precisely to avoid remote theft. A firmware flaw that leaks the seed generation process means no amount of offline storage or physical security can protect funds. For the broader ecosystem, the incident will likely accelerate demand for audited, verifiable random number generation in all hardware wallets. Regulators may also take notice, potentially requiring minimum security standards for devices marketed as secure storage. The $88 million loss represents not just stolen money but a shattered confidence in one of the most trusted names in Bitcoin security.

What Comes Next for Coldcard

Coldcard has released a firmware update to address the seed generation flaw, but the damage is done. Users must transfer remaining funds to newly generated wallets with updated firmware and ideally using a different random number source. The company has not announced a compensation plan for victims. Meanwhile, the crypto community is debating whether hardware wallets need independent third-party audits of their random number generation, not just of their firmware code. This incident shows that even a single weak link in the security chain can lead to catastrophic losses.