Critical Security Flaw in Coldcard Hardware Wallets Leads to $89 Million Bitcoin Theft
Owners urged to migrate funds immediately as researchers reveal a firmware bug may have allowed attackers to predict recovery phrases and drain wallets remotely

Owners of Coldcard, one of the most popular hardware wallets for storing Bitcoin, are being urged to take immediate action after security researchers discovered a critical software vulnerability that has already resulted in the theft of approximately $89 million worth of cryptocurrency.
The breach, first reported by Forbes, involves a coding error in certain versions of the Coldcard firmware that potentially weakened the device’s core security feature: the generation of recovery phrases (also known as seed phrases). According to analysts at Galaxy Research, hackers exploited this flaw to drain more than 1,000 Bitcoin from 1,196 digital wallets in a span of just 41 minutes on July 30. Subsequent analysis identified two additional waves of suspicious activity, pushing the total estimated losses to nearly $89 million.
How the Attack Worked
Hardware wallets like Coldcard are designed to keep cryptocurrency offline, protecting it from internet-based hacks. However, Block’s Bitcoin Engineering and Security team revealed that a specific coding mistake in older Coldcard firmware versions made some recovery phrases predictable under certain circumstances.
This vulnerability did not require physical access to the device. Instead, sophisticated attackers could theoretically calculate or guess the recovery phrases generated by the flawed software, allowing them to steal Bitcoin remotely without ever touching the user’s hardware.
"The issue involves a coding mistake... that may have weakened one of the wallet's key security features," Block stated in its advisory. The firm emphasized that its findings are based on blockchain analysis and that while not every affected wallet has been definitively linked to the bug, the pattern of transactions strongly suggests a systemic exploit.
Coinkite’s Response: "Heartbroken" and Urgent Action Required
Coinkite, the Canadian company behind Coldcard, has released a firmware update to prevent the vulnerability from affecting newly created wallets. However, the company issued a stark warning: updating the firmware does not fix wallets that were already created using the affected software.
Because the weakness lies in the mathematical generation of the recovery phrase itself, simply installing the new update leaves existing funds vulnerable. The only way to secure assets is to generate a brand-new recovery phrase using the updated firmware and migrate all Bitcoin to this new, secure wallet.
"Updating the firmware does not repair a seed that was generated by affected firmware," Coinkite said in a security advisory. "A new seed must be generated, and the funds migrated to the new wallet."
Coinkite CEO Rodolfo Novak issued a public apology on social media platform X, expressing deep regret over the incident.
"I'm sorry, and I'm devastated," Novak wrote. "Our team is heartbroken about yesterday's news. We are taking full accountability for the firmware bug."
Novak urged customers to act with extreme urgency, noting that attacks appear to be ongoing. "If you generated a seed using a Coldcard wallet, move your funds now, using our updated best practices, before reading further," he pleaded. "Some affected users may not be watching social media right now, and every hour matters."
Who Is Affected?
Initially, the warning focused on older Coldcard models, but Coinkite has since expanded the list of affected products to include additional models and software versions. The company noted that users who generated their recovery phrases using at least 50 private dice rolls (a method that adds external entropy to the process) are likely not affected by this specific flaw. However, for anyone unsure of how their wallet was set up, Coinkite recommends creating a new recovery phrase and migrating funds as a precaution.
Coinkite stated it is still determining the full scope of the issue and plans to publish a detailed technical explanation once its investigation is complete. The company is also cooperating with law enforcement agencies, including the FBI and the Royal Canadian Mounted Police (RCMP), and is assisting affected customers with police reports and insurance claims.
Industry Reaction and Other Wallets
The warning spread rapidly across the cryptocurrency community. Samson Mow, CEO of Jan3, posted an urgent alert on X: "If you're using a COLDCARD, any version firmware or MK, migrate your funds immediately. If you know someone who is, let them know ASAP... Attacks are ongoing so do it quickly."
Meanwhile, developers of other popular hardware wallets moved to clarify their status. Bitkey, the wallet developed by Block (formerly Square) and co-founded by Jack Dorsey, addressed rumors of a similar vulnerability. Developer Clay Garrett stated that while they are investigating a separate reported issue, it does not pose an immediate threat.
"Our assessment is this presents no risk of remote drains or immediate funds loss," Garrett wrote, advising Bitkey users to continue using their wallets normally. He noted that exploiting the reported Bitkey issue would require "exceptional circumstances" and would not provide enough information for an attacker to steal funds.
Block also confirmed that none of its own products or customers are affected by the Coldcard vulnerability.
What Users Should Do Now
Check Your Firmware: Determine if your Coldcard device was used to generate a recovery phrase with a potentially affected firmware version.
Do Not Just Update: Remember that updating the firmware alone is insufficient for existing wallets.
Migrate Funds: Generate a new recovery phrase using the latest Coldcard firmware and transfer all Bitcoin to this new wallet.
Spread the Word: Help inform other Coldcard owners who may not be active on social media, as time is critical.
As the investigation continues, this incident serves as a sobering reminder of the complexities of self-custody in the cryptocurrency world. Even devices designed for maximum security can harbor hidden vulnerabilities, making vigilance and prompt action essential for protecting digital assets.
About the Creator
Mark Lim
Hi I am mark an automotive student and a car, tech and food enthusiast ! Im gonna try and post daily & hope you enjoy what I write and do share my page with people you know. I would gladly appreciate it! Cheers
Enjoyed the story? Support the Creator.
Subscribe for free to receive all their stories in your feed. You could also become a paid subscriber, letting them know you appreciate their work.
Comments
There are no comments for this story
Be the first to respond and start the conversation.