Hackers drained 594 bitcoins, worth roughly $38 million, from hundreds of Coldcard hardware wallets in a lightning-fast operation lasting just 25 minutes. The breach exploited a critical vulnerability introduced in the wallet's firmware back in March 2021. Instead of relying on the device's hardware randomness to secure cryptographic keys, affected wallets fell back to a predictable, software-based process. This glaring weakness turned supposedly unguessable seeds into easily compromised ones.

Between 01:31 and 01:56 UTC on a recent Friday, attackers swept funds from about 500 single-signature wallets, each holding at least 0.15 BTC, many of which had been inactive for years. The stolen coins spanned creation dates from 2021 to 2026, reflecting the lifespan of the flawed firmware versions. After grabbing the funds through 1,324 separate transactions, the thief consolidated 562 BTC into one address that has not moved since.

How the Wallet’s Randomness Failed

The problem stemmed from Coldcard's firmware version 4.0.0, which instructed the device to skip its hardware-based randomness generator when creating seeds. Instead, it defaulted to a software method seeded by non-secret chip data. This unintended fallback made it possible for attackers to reconstruct wallet seeds by guessing values that should have been practically impossible to predict. Coldcard's parent company, Coinkite, confirmed the issue affects wallets generated on Mk3 devices running firmware 4.0.1 or earlier. Newer models like Mk4, Q, and Mk5, running updated software, appear immune. Despite the large theft, bitcoin’s market price remained surprisingly stable and unaffected.

This incident highlights the risks inherent in small hardware wallet manufacturers and the importance of truly random seed generation. It also follows other recent security concerns in the hardware wallet space, including increased scrutiny of Coldcard’s Mk3 firmware after suspicious $38 million bitcoin movements raised alarms. Users who created wallets on vulnerable versions are advised to move funds to safer devices and firmware immediately.

This article is for informational purposes and does not constitute financial advice.