Coldcard Vulnerability Drains Millions as Old Firmware Bug Puts High-Security Wallets at Risk
A long-dormant Coldcard firmware flaw has spiraled into one of the biggest self-custody thefts of the year, with estimated losses now approaching $114 million in bitcoin. The exploit traces back to a 2021 build error that weakened seed generation on affected devices, allowing attackers to drain funds without physically touching the wallets.
Researchers and industry reports say the thefts have unfolded in multiple waves, with one early round draining about 1,082.65 BTC worth roughly $70.2 million and later sweeps pushing the total to about 1,816 BTC.15 Galaxy Research and other trackers said the damage climbed further after a fourth wave of attacks, lifting the estimated loss near $114 million.
A build error with long tail damage
The flaw reportedly came from a firmware build mistake that caused some Coldcard devices to generate wallet seeds from a much smaller pool of randomness than intended. That reduced entropy made private keys far easier to brute-force than users would expect from a high-security hardware wallet.
The vulnerability was linked to firmware introduced in March 2021 and appears to have affected multiple Coldcard models and build variants. Reporting also indicates the problem was not in Bitcoin itself, but in the wallet’s seed-generation process.
Why the losses keep rising
The attacks have reportedly continued in waves, with researchers observing repeated sweeps across thousands of addresses. Some reports described the later activity as unusually rapid, with attackers moving funds across many addresses in a short period.
The scale of the losses has also shifted as more compromised wallets were identified and updated pricing changed the dollar value of stolen bitcoin. That is why different outlets have cited figures ranging from roughly $89 million to about $114 million.
What it means for self-custody
The Coldcard incident is a reminder that even highly regarded hardware wallets can fail if randomness or build processes break. For users, it reinforces the need to verify firmware versions, move funds from affected devices, and treat seed generation as a critical security dependency.
It also highlights a broader lesson for crypto security: strong physical design does not eliminate software risk. In self-custody, one hidden build mistake can become an expensive chain reaction years later.
Disclaimers: All contents in this article are for informational purposes only and does not constitute any form of advice.Third-party websites and their content are provided for informational purposes and user convenience only. Rola News does not control, endorse, or assume responsibility for any Third-party websites, including their content, accuracy, privacy practices, or any subsequent changes or updates made to them. This article is AI-assisted and has been reviewed by our editorial team.