In This Article
- What Happened in the Coldcard Hack?
- How the Coldcard Vulnerability Worked
- Which Coldcard Wallets Are Affected?
- Installing the Update Does Not Protect an Existing Seed
- Coldcard Incident Triggers Largest Small-Bitcoin Movement Since FTX
- Jameson Lopp Says the Hack Exposes the Limits of “Don’t Trust, Verify”
- Can the Stolen Bitcoin Be Recovered?
- What Happens Next?
The amount of Bitcoin stolen in the Coldcard wallet hack has climbed above $100 million. Galaxy Research now estimates that 1,596 Bitcoin was stolen from approximately 7,300 addresses across three confirmed attack waves and 14 smaller incidents.
The company is also investigating a suspected fourth wave that could raise the total to 2,055 BTC, worth approximately $130 million. Galaxy said it received reports from 73 victims, which helped researchers confirm the first three major waves and identify smaller transaction patterns that may be additional attackers exploiting the same weakness
The latest estimate is much higher than the roughly $70 million that was initially associated with the incident. It also explains why figures have differed across reports published as the attack developed.
What Happened in the Coldcard Hack?
The incident first attracted widespread attention after a large Bitcoin sweep on July 30. During the opening attack wave, approximately 1,082.65 BTC was removed from 1,196 addresses in only 41 minutes. The Bitcoin was worth about $70.2 million at the time. Researchers connected the affected addresses to recovery seeds generated by vulnerable Coldcard firmware.
Security Advisory released by Coinkite on July 30
Two additional waves followed. By Aug. 2, researchers traced approximately 1,367 BTC across 4,585 addresses. The third wave targeted smaller balances, and took roughly 208 BTC from 1,912 addresses while using a different transaction structure from the earlier attacks.
Galaxy said that each wave looks internally consistent with the actions of a single operator. However, researchers have not established that the same attacker controlled all three waves. Once the vulnerability became public, other parties may also have started searching for and draining the affected wallets.
The latest investigation raised the confirmed total to 1,596 BTC across three major waves and 14 smaller incidents. Galaxy has not included the suspected fourth wave in its confirmed estimate because it has not received sufficient victim confirmation for that group of transactions.
How the Coldcard Vulnerability Worked
The Coldcard incident was not a compromise of the Bitcoin network itself. Attackers exploited weak recovery seeds generated by certain versions of Coldcard’s firmware.
A Bitcoin hardware wallet normally creates a recovery seed using cryptographically secure random information. This randomness, known as entropy, makes it effectively impossible for another person to guess the seed and recreate the wallet’s private keys.
Coldcard’s problem began during a firmware change that was introduced in March of 2021. Wallet seed generation was moved from Coldcard’s hardware random-number generator to a function provided through the libNgU and MicroPython software stack.
Because of an integration error, the seed-generation process reached MicroPython’s deterministic software fallback instead of Coldcard’s intended hardware random-number generator. That fallback relied heavily on device information and timing values rather than a sufficiently unpredictable cryptographic source.
The resulting seeds could appear random while actually belonging to a much smaller range of possible combinations. An attacker could generate potential seeds offline, derive their corresponding Bitcoin addresses and compare them with publicly visible addresses on the blockchain.
Example of recovery seep phrases
This meant the attackers did not need to steal, connect to or physically access a victim’s Coldcard. They could reproduce candidate keys remotely using computing resources and then transfer funds when a matching address was found.
Coinkite estimates that affected Mk2 and Mk3 seeds had an effective search space of about 40 bits rather than the intended security level. The Mk4, Mk5 and Q models received additional randomness from their secure elements, but Coinkite estimates that those wallets still achieved only about 72 bits of entropy instead of the intended 128 bits.
Which Coldcard Wallets Are Affected?
According to Coinkite’s current security advisory, the vulnerability affects seeds generated on the following firmware:
- Mk2 and Mk3 devices using versions 4.0.1 through 4.1.9.
- Mk4 and Mk5 devices before standard firmware 5.6.0.
- Mk4 and Mk5 devices using Edge firmware before 6.6.0X.
- Coldcard Q devices before standard firmware 1.5.0Q.
- Coldcard Q devices using Edge firmware before 6.6.0QX.
TAPSIGNER, OPENDIME and SATSCARD are not affected because they use different codebases.
(Source: ColdCard.com)
The important factor is the firmware running when the seed was originally generated—not the firmware currently installed on the device. Moving a vulnerable seed to another Coldcard or a wallet made by a different company does not make it secure.
Installing the Update Does Not Protect an Existing Seed
Coinkite has released fixed firmware for the affected devices. However, installing the update does not repair a recovery seed that was created by vulnerable firmware.
An affected user must first install the fixed firmware and then generate an entirely new recovery seed. The user should verify the new wallet fingerprint and receiving address, send a small test transaction and move the remaining balance only after confirming that the new wallet works correctly.
Importing the old recovery words into updated firmware does not solve the problem. The weakness belongs to the seed itself and follows it to any device or wallet application where it is restored.
Coinkite says seeds created with at least 50 fair, independent and private dice rolls are not considered vulnerable to this specific entropy flaw. The company also says that a strong and unique BIP-39 passphrase creates an additional barrier, although it still recommends replacing the underlying seed. A Coldcard PIN is not the same as a BIP-39 passphrase.
Users should never enter their recovery words into a website claiming to check whether a wallet is affected. Doing so would hand control of the wallet directly to whoever operates the website.
Coldcard Incident Triggers Largest Small-Bitcoin Movement Since FTX
The warning prompted a major movement of Bitcoin held in smaller addresses.
Transfers involving less than 1 BTC reached 39,600 BTC in one day, according to CryptoQuant research head Julio Moreno. That was the highest daily amount recorded for this category since November of 2022, shortly after the collapse of FTX, when approximately 39,900 BTC was moved.
After FTX collapsed, users moved funds away from centralized exchanges and into self-custody. During the Coldcard incident, some users moved coins away from potentially affected self-custody wallets, including temporary transfers to exchanges or newly generated wallets.
The activity does not mean every small transfer came from a Coldcard user. However, the timing suggests that the security warning contributed to the sharp increase.
Jameson Lopp Says the Hack Exposes the Limits of “Don’t Trust, Verify”
The incident also reopened the debate over whether average Bitcoin owners can realistically verify every component of a self-custody system.
Bitcoin security researcher and Casa co-founder Jameson Lopp argued that the Coldcard failure does not invalidate self-custody. Instead, it proves that most people cannot personally audit the complex software, firmware and hardware they use.
Users still depend on wallet manufacturers, developers and security researchers to test systems they cannot independently verify. Lopp’s bigger point was that Bitcoin users should avoid placing all their trust in one company, one device or one security mechanism.
Can the Stolen Bitcoin Be Recovered?
Galaxy Research said approximately 90% of the stolen Bitcoin is still unmoved in its latest update. Researchers have shared suspected attacker and victim addresses with US federal law enforcement agencies, cryptocurrency exchanges and cyber-investigation companies.
The fact that most of the Bitcoin has not moved may give exchanges and investigators time to monitor the addresses. However, unmoved Bitcoin is not necessarily recoverable. Bitcoin transactions cannot simply be reversed, and recovery may depend on the attacker transferring funds to a regulated service that can identify or freeze them.
Currently, no attacker attribution, confirmed recovery of the stolen funds or comprehensive victim compensation plan had been publicly announced.
What Happens Next?
The confirmed loss figure could continue changing as more victims report affected addresses and researchers investigate the suspected fourth wave.
The main questions are whether the fourth cluster can be confirmed, whether the stolen Bitcoin begins moving through exchanges or mixing services and whether investigators can identify more than one attacker.
For Coldcard users, the most important point is that a firmware update alone is not enough. Anyone whose seed may have been generated by affected firmware must replace that seed and move the funds to a newly generated wallet.