Coldcard firmware flaw linked to $38 million Bitcoin loss in 25 minutes
A firmware build error affecting Coldcard hardware wallets has been linked to the theft of approximately 594 BTC, valued at about $38 million at the time. The Bitcoin was drained from roughly 500 wallets within 25 minutes on July 31, after an attacker exploited weak private-key generation rather than phishing, malware or physical access.
Key takeaways
- Approximately 594 BTC was taken from about 500 Coldcard wallets in 25 minutes.
- A firmware build mistake caused some devices to generate predictable seeds.
- Mk3 wallets reportedly had about 40 bits of effective entropy instead of 128.
- Updating firmware does not repair seeds created before the fix.
- The incident underscores why security, transparency and layered custody matter.
How the firmware error weakened wallet security
Coldcard maker Coinkite said a build configuration error caused seed generation to select a software fallback instead of the intended hardware random-number generator. The relevant code contained two functions with the same signature, while a preprocessor check evaluated whether a setting existed rather than whether it held the correct value.
The build completed without warnings and produced normal-looking wallet addresses. However, the resulting private keys were substantially less random than users expected. The issue reportedly existed from firmware version 4.0.1, released in March 2021, until patches issued in July 2026.
Coinkite estimated that affected Mk3 seeds had roughly 40 bits of effective entropy. The Mk4, Q and Mk5 models reportedly benefited from additional secure-element entropy but still reached only about 72 bits under the flawed process.
The attack and its wider exposure
The sweep began at 2:14 a.m. UTC and ended around 2:39 a.m. Bitcoin moved from hundreds of wallets into a consolidation address, with 562 BTC later held at a single address. The coordinated timing suggests that the attacker had identified vulnerable keys in advance rather than acting opportunistically.
The immediate loss may not represent the full exposure. Any seed generated on affected firmware could require review, including wallets that were not targeted during the initial transaction sequence. The five-year vulnerability window also complicates efforts to determine how many users may be affected.
Why a firmware update is not enough
A firmware patch can correct future seed generation, but it cannot strengthen a seed that already exists. Owners of potentially affected wallets must create a replacement seed using patched firmware and transfer funds to addresses controlled by the new wallet. That process should be handled carefully because a known weak key may be monitored by an attacker.
Multisignature users face a different migration process. If only one signing key was generated on affected firmware, the arrangement may retain protection from the remaining keys, but replacing the compromised signer remains important for restoring the intended security model. Users who incorporated substantial independent dice entropy may have reduced or eliminated the weakness, although the manufacturer has still urged caution.
What the incident means for crypto security
Coinkite said it believes artificial intelligence may have helped identify the flaw, while its own AI-assisted review had not detected it weeks earlier. That claim remains unverified. More broadly, the episode shows that open-source code and automated review are useful safeguards but are not substitutes for rigorous human testing, build verification and independent audits.
For exchanges such as Bitval, the lesson is structural: security controls must be supported by transparent operations, resilient infrastructure and disciplined risk management. Hardware wallets can reduce certain risks, but no single device should be treated as infallible when significant assets are involved. Strong infrastructure outlasts noise, while trust is earned slowly and lost quickly.
What to monitor next
Attention will likely focus on whether the stolen Bitcoin moves, whether additional vulnerable wallets are drained and how quickly affected users complete migrations. The incident may also prompt deeper disclosure from wallet manufacturers about entropy generation, build pipelines and audit coverage.
Crypto users should assess custody arrangements through a long-term risk lens and conduct their own research. This article is for educational purposes only and is not financial or security advice. For users who choose to trade, Bitval.com provides a transparent interface, audited infrastructure and clearly disclosed fees designed around stability and responsible access.