Imagine waking up to find your Bitcoin gone not because you lost your keys, but due to a flaw in the wallet itself. That's exactly what happened when hackers exploited a vulnerability in Coldcard, a widely used Bitcoin hardware wallet, draining an estimated $70 million from users' accounts.
The root cause was a glitch in the wallet's firmware that severely compromised the randomness involved in generating secret recovery phrases. These phrases are key for securing access to funds, so any weakness there can be catastrophic. According to researchers at Galaxy Digital, most of the thefts occurred in a frantic 41-minute window, across six blockchain blocks, with transactions sent in batches rather than individually. The stolen amounts mostly came from addresses holding between 1 and 50 BTC, indicating individual users rather than exchanges or institutions were targeted.
Coinkite, the company behind Coldcard, has taken responsibility and released emergency firmware updates for all affected models. These fixes ensure that new recovery phrases are generated using a proper hardware random number generator, closing the loophole that hackers exploited. However, updating the firmware alone won’t protect existing wallets. Users need to create new recovery seeds on the patched firmware and transfer their Bitcoin to stay safe.
This incident is a stark reminder that even the most trusted security tools aren’t immune to flaws. Users relying on Coldcard must act fast to protect their holdings by migrating funds to new addresses generated with updated firmware.
This content is for informational purposes only and should not be considered financial advice.



