A firmware bug that sat dormant in Coldcard hardware wallets since 2021 just cost users nearly $89 million. Attackers drained 1,367 BTC from over 4,500 devices by exploiting a predictable random number generator that was supposed to be impossible to crack offline.
The vulnerability lived in Coldcard versions 4.0.0 through 5.0.3. Back in March 2021, the company switched from a hardware-based true random number generator to a software fallback that turned out to be predictable. An attacker could sit at a computer, brute-force the seed phrases, and unlock wallets without ever touching the internet or the physical device.
Galaxy Research documented three attack waves, all pointing to a single operator working methodically. The first hit on July 30, draining 594 BTC from roughly 500 wallets in about 25 minutes. By August 2, the total had climbed to 1,367 BTC across 4,585 compromised addresses. Every stolen wallet had one thing in common: none used a BIP-39 passphrase. Multisig setups stayed safe.
This cuts deep at the core promise of air-gapped hardware wallets. The whole appeal is that your keys never touch the internet. Your seeds stay offline, locked away from hackers and malware. Coldcard built its reputation on exactly that guarantee. A five-year window where that guarantee didn't actually hold is the kind of revelation that shakes confidence in self-custody hard. Users who thought they were protected discovered they weren't, and the damage is already done.
This article is for informational purposes only and should not be construed as financial advice. Always verify security practices and firmware versions on your hardware wallets.



