Coldcard Wallet Hack Drains $88 Million, Bitcoin Network Remains Secure

A security failure involving Coldcard hardware wallets (not the Bitcoin network itself) has reportedly exposed private keys controlling approximately 1,367 BTC, valued near $88.6 million at the time of reporting.

Coldcard is a Bitcoin-only hardware-wallet brand manufactured by Canadian company Coinkite.

On-chain researchers identified three suspected theft waves affecting thousands of Bitcoin addresses generated through vulnerable Coldcard devices.

Bitcoin’s blockchain, mining network and consensus rules continued operating normally; the attackers gained access by exploiting weak wallet credentials rather than breaking Bitcoin’s cryptography.

The vulnerability was connected to how certain Coldcard firmware versions generated wallet seeds—the recovery phrases from which private keys are derived.

Coinkite’s advisory says affected firmware produced less randomness, or entropy, than users should have received.

This made some seeds easier for attackers to reconstruct through offline computation, allowing them to sign valid Bitcoin transactions without physically stealing the devices.

Coldcard Mk2 and Mk3 wallets running versions 4.0.1 through 4.1.9 were specifically identified as vulnerable, while seeds generated on some Mk4, Mk5 and Q firmware releases were also affected unless users added sufficient private dice-roll entropy or protected the wallet with a strong, unique BIP-39 passphrase.

The distinction matters: Bitcoin was not hacked, reversed or compromised.

The affected wallets contained flawed or weakened keys, and possession of a valid private key gives an attacker legitimate control over the associated coins under Bitcoin’s rules.

Coinkite has released corrected firmware, but updating a device cannot repair an old seed that was generated with vulnerable software.

Users with potentially affected seeds must create a new seed using fixed firmware and move their Bitcoin to newly generated addresses;

Coinkite also confirmed that its TAPSIGNER, OPENDIME and SATSCARD products use different codebases and were not affected by this particular bug.

BitcoinVersus.Tech Editor’s Note:

We volunteer daily to ensure the credibility of the information on this platform is Verifiably True. If you would like to support to help further secure the integrity of our research initiatives, please donate here: 3C9o19EH5HSiwEPyCTmEKzxhNCbo2X6TTb

BitcoinVersus.tech is not a financial advisor. This media platform reports on financial subjects purely for informational purposes.

Leave a comment