Over the weekend, hackers drained nearly 450 Bitcoin from hundreds of Coldcard wallet users, marking the fourth wave of attacks linked to a critical firmware flaw.

Research firm Galaxy Research tracked the breach to 709 addresses, suspected victims based on transaction behavior. Total losses across all four waves now approach 1,815 Bitcoin taken from over 5,000 addresses. The exact toll remains uncertain, as some victims might overlap and Coinkite, the wallet maker, has not confirmed all numbers.

Coinkite traced the vulnerability back to a 2021 firmware update that swapped out the device’s original hardware-based random number generator for a weaker software fallback. This meant wallet seeds were generated with less entropy, making them easier to predict and exploit.

The affected Coldcard models include Mk2, Mk3, Mk4, Mk5, and Q, each compromised to varying degrees. The company has halted shipments, destroyed vulnerable stock, and released patched firmware. Still, users must generate new seeds and move their funds to stay safe.

Kraken’s security chief Nick Percoco highlighted the case as a warning. Unlike other hardware devices, cryptocurrency wallets lack rigorous independent testing for critical security features, leaving users exposed to silent but severe risks.

Block’s engineering team independently reviewed the flaw but has not confirmed if the exploit is fully practical beyond reported thefts. Nevertheless, they support early disclosure to warn the community.

This incident serves as a stark reminder that even trusted hardware wallets can harbor hidden vulnerabilities for years. Coldcard users should urgently verify their balances and upgrade their devices to new seeds.

This material is for informational purposes only and does not constitute financial advice.