Coldcard Exploit May Have Removed Up to 2,055 BTC Globally

Galaxy Research confirms 1,596 BTC stolen from Coldcard seed‑generation flaws across three waves, with a potential fourth wave raising losses to 2,055 BTC. Most funds remain unmoved; users must update firmware and migrate seeds.

Coldcard Exploit May Have Removed Up to 2,055 BTC Globally
Reading time: 6 Minutes
Follow on Google

Massive Coldcard losses under investigation

Galaxy Research now estimates that confirmed thefts related to a Coldcard hardware wallet vulnerability total 1,596 Bitcoin across three verified attack waves. If a suspected fourth wave is confirmed, the tally could rise to about 2,055 BTC—nearly $130 million at current market prices. Investigators have been sharing attacker and victim addresses with U.S. law enforcement, major exchanges and private cyber‑forensics teams as the probe continues.

Confirmed losses, potential fourth wave and methodology

Galaxy Research's latest public update clarifies the distinction between confirmed and suspected thefts. The firm has high confidence in the 1,596 BTC figure, which it ties to roughly 7,300 affected addresses across three confirmed waves and a series of smaller incidents (about 14). The larger 2,055 BTC number remains conditional pending victim confirmations for a suspected fourth wave.

Earlier on‑chain estimates had identified approximately 1,815.75 BTC moving across four observed waves, but Galaxy emphasized those figures were derived from blockchain activity alone and lacked direct confirmation from wallet owners. The new update tightens the confirmed totals while preserving the higher potential loss if additional victims corroborate the fourth wave.

Blockchain signals and address mapping

Galaxy observed transaction patterns in the suspected fourth wave that closely match the earlier compromises, including concentrated sweeps and similar transfer behaviors. The research team assigned medium‑high confidence that most of the suspected fourth‑wave activity was executed by a single attacker, while noting blockchain analysis cannot definitively prove operator identity or confirm every victim address without independent reporting.

Investigators continue to refine address mapping as more victims and third parties provide details. Galaxy has shared lists of confirmed attacker and victim addresses with U.S. federal law enforcement, exchanges and private cyber investigation groups to enable real‑time monitoring and potential freezing or tagging of suspicious funds.

Root cause — RNG fallback introduced in 2021 firmware

The vulnerability traces back to a March 2021 firmware change. When Coinkite integrated a new cryptographic library into Coldcard firmware, the device’s seed generation logic incorrectly used a deterministic pseudo‑random fallback provided by MicroPython rather than the hardware true random number generator (TRNG) during wallet creation.

That mistake meant seeds generated on affected Coldcard Mk3, Mk4, Mk5 and Coldcard Q models running vulnerable firmware versions were created with far less entropy than intended. Internal code reviews could still detect the presence of the hardware TRNG in other parts of the firmware, which obscured the issue and delayed detection.

Block’s Bitcoin engineering and security team independently reviewed the firmware and reached the same conclusion: the vulnerable builds invoked the deterministic MicroPython fallback instead of calling the STM32 hardware random‑number generator at seed creation.

Coinkite’s technical assessment estimates effective entropy for some affected models was significantly reduced. Mk2 and Mk3 devices may have provided roughly 40 bits of effective entropy, while vulnerable Mk4, Mk5 and Coldcard Q units may have generated around 72 bits of entropy—well short of the expected 128 bits.

Where the stolen Bitcoin stands — most funds unmoved

Galaxy reports roughly 90% of the stolen Bitcoin remains untouched in attacker‑controlled addresses. None of the coins stolen during the three confirmed waves have moved since initial extraction, which gives investigators valuable time to track, tag and coordinate responses with exchanges and law enforcement.

Analysis shows attackers largely avoided consolidating funds into a single central wallet; instead they distributed balances across many new addresses and sometimes used second‑hop transfers that make tracing more complex. During the suspected fourth wave, Galaxy observed a sharp increase in wallet sweeps—about 13.8 sweeps per Bitcoin block—compared with roughly 0.3 sweeps per block prior to the incident.

Galaxy also warned that new opportunistic attackers could try to exploit the same vulnerability while affected devices remain in circulation. Identifying attacker‑controlled addresses and monitoring funds therefore remains a priority so exchanges and authorities can act quickly if coins begin to move.

Replace‑by‑Fee and recovery limits

Galaxy noted a narrow recovery window exists only in limited circumstances: users who still control compromised wallets might be able to replace an unconfirmed theft transaction using Bitcoin’s Replace‑by‑Fee (RBF) mechanism. That option is only available before miners confirm the original transaction and provides no guarantee of success. Once a theft is confirmed on‑chain, recovery options become far more limited and rely on law enforcement or coordination with centralized services.

Coinkite response and firmware updates

Coinkite released emergency firmware updates for all affected product lines. Published fixes include firmware 4.2.0 for Mk2 and Mk3 devices, 5.6.0 for Mk4 and Mk5 models, 1.5.0Q for Coldcard Q, and Edge releases 6.6.0X and 6.6.0QX. The company also reported it destroyed remaining inventory that contained vulnerable firmware.

Crucially, Coinkite warns that installing updated firmware only protects wallets created after the fix. Seed phrases generated with the vulnerable firmware remain exposed and should be considered compromised. The company recommends generating a brand‑new seed on patched hardware and migrating funds immediately.

Coinkite's migration guidance

Coinkite’s recommended migration steps are standard best practices for hardware wallet security:

  • Update the device firmware to the fixed release for your model.
  • Generate a completely new wallet seed on the patched device.
  • Verify a receiving address on the new wallet and send a small test transaction.
  • Once the test confirms, transfer the remaining balance to the new wallet.

Coinkite also notes that wallets created using at least 50 fair private dice rolls are not vulnerable to this RNG fallback alone, and a robust BIP‑39 passphrase adds an extra layer of protection. Still, Coinkite continues to urge migration because the original seeds created under the defective entropy source are inherently weak.

What Coldcard users and the broader crypto community should do

If you own a Coldcard device, act with urgency:

  • Check your device model and firmware version; install Coinkite’s emergency update if you haven’t already.
  • Assume any seed generated on vulnerable firmware is compromised and migrate funds to a new seed created on patched hardware.
  • Avoid reusing old passphrases or partially migrating; perform full migrations and confirmations as recommended.
  • Monitor public address lists and watchlists maintained by investigators and exchanges for attacker addresses.

For exchanges, custodians and custodial services: prioritize address monitoring and rapid response procedures. Tagging and freezing incoming tainted funds can limit attacker liquidity and assist law enforcement investigations.

Investigation status and next steps

The investigation remains active. Galaxy Research continues to refine its on‑chain mappings and is awaiting direct victim confirmations to either validate or rule out the suspected fourth wave. Because most stolen BTC has not moved, there remains a real opportunity for coordinated action by law enforcement, exchanges and private cyber‑forensics teams.

This incident underscores an enduring truth for crypto security: firmware and entropy sources are foundational to hardware wallet safety. Even widely trusted devices can be exposed by subtle software regressions. Users, manufacturers and auditors should treat seed generation and TRNG integration as critical attack surfaces requiring independent review and robust testing.

For now, affected Coldcard owners should assume compromised seeds are irrecoverable and migrate funds immediately. Exchanges and investigators should keep monitoring suspect addresses and cooperate to limit attacker options if funds start to shift.

Elias Moreau

“I cover automotive innovation, electric vehicles, and the future of mobility — where technology meets sustainability.”

Leave a Comment

Comments

No comments yet. Be the first.