Coldcard key entropy blunder fuels $100M+ drain as small BTC holders stampede to CEXs
Confirmed losses from the Coldcard hardware-wallet incident have crossed $100 million, with Galaxy Research tracking 1,596 $BTC stolen from roughly 7,300 addresses across three confirmed attack waves and 14 smaller incidents. The firm identified a suspected fourth wave that could lift observed losses to about 2,055 $BTC, roughly $130 million at current prices, though it excluded that figure from its confirmed tally because no victim has yet verified participation. Three waves totalling 1,367 $BTC across 4,585 addresses were documented by Saturday, including a third wave that drained 207.7294 $BTC from 1,912 addresses. Galaxy Research said 73 victims had contacted its investigators, and 90% of the stolen $BTC has not moved. Attacker and victim addresses have been shared with U.S. federal law enforcement, crypto exchanges and cyber-investigation firms.
"I continue to investigate and add new Coldcard victim and attacker addresses to our investigation database. The attack is ongoing—move your funds off Coldcard-generated addresses immediately if you have not done so," Galaxy head of research Alex Thorn posted to X. On Monday, Thorn flagged 218 transactions in roughly 15 consecutive blocks affecting 462 potential victim addresses, moving about 388.9 $BTC; after correcting a set that had wrongly included multisig addresses, he put the fourth wave at 709 addresses and 448.73 $BTC, around $28 million. Average sweeps ran at 13.8 per block, about 45 times the rate observed in a pre-incident control window, with some transactions still sitting unconfirmed in the mempool and opted into replace-by-fee. Galaxy said it had flagged roughly 600 suspected attacker addresses to federal investigators and compliance firms.
The original incident, according to Galaxy Research, involved 1,196 addresses linked to 1,082.65 $BTC, worth about $70.2 million at the time, moved between 1:10 AM and 1:51 AM UTC on July 30 across blocks 960,183 to 960,191, about 30 hours before Coinkite published its first security advisory. Earlier preliminary analysis by AnchorWatch CEO Rob Hamilton estimated 594.48 $BTC, worth around $38 million, across 500 transactions in a three-block window. Galaxy Research said the identified transactions shared a pattern, including identical 30 satoshis per virtual byte fees and no change outputs, which it used to flag the initial attack on-chain, and noted that future attacks against Coldcard-generated addresses may not follow the same fingerprint.
Coinkite co-founder Rodolfo Novak said in an X post on Friday that the company takes responsibility for the firmware bug and is working to determine the full scope of the issue. He said Coinkite released a hotfix to remove the software fallback path, but warned the update does not protect seeds generated on vulnerable firmware. In a technical backgrounder, Coinkite said the March 2021 firmware migration onto libsecp256k1 quietly rerouted seed generation away from Coldcard's hardware random number generator and onto MicroPython's software fallback, a small pseudo-random algorithm called Yasmarang. A build guard used #ifndef, which checks whether a setting exists rather than whether it is switched on, and Coinkite had defined that setting as zero, meaning "off"; because zero still counts as defined, the safety check passed. "The bulk of randomness on the COLDCARD was coming from a PRNG that I didn't know was actually in the source code base," Coinkite wrote. On Mk2 and Mk3 devices running firmware 4.0.1 through 4.1.9, the starting value came from the chip's serial number and its clock, yielding a search space of about 40 bits; newer models mixed in limited secure-element entropy, lifting them to roughly 72 bits. Block's Bitcoin engineering team found that a firmware integration error routed random-number generation through a deterministic MicroPython fallback instead of the intended hardware source, and its report said Mk2 and Mk3 devices on vulnerable firmware added no cryptographic entropy through that path.
Coinkite's security advisory covers Mk2 and Mk3 firmware from version 4.0.1 through 4.1.9, plus seeds generated on Mk4, Mk5 and Q devices before their fixed releases. The company said at least 15 separate attackers have piled in, and the bulk of stolen coins had sat untouched for years before being taken, with an average dormancy of 3.18 years. Coinkite estimates the resulting search space at about 40 bits. Thorn wrote that the sweeps look deliberate and programmatic, probably orchestrated with a large language model, and cautioned that every single-sig Coldcard address created after that 2021 update will eventually be drained, saying it is only a matter of time.
The news triggered a rush of small holders moving coins. CryptoQuant head of research Julio Moreno said transfers of less than 1 $BTC totaled 39,600 $BTC (around $2.5 billion) on July 31, the last comparable figure being 39,900 $BTC on November 16, 2022, days after FTX failed. Daily active addresses rose from 645,000 on July 30 to almost a million on July 31, the highest since December 2024, with the jump concentrated in sending addresses rather than receiving ones. Sub-10 $BTC deposits to exchanges hit 7,300 $BTC ($459 million) on July 31, the most since February 6, and $BTC was trading at $62,724, down 0.7% over the past day, per CoinGecko data.
Bloomberg Intelligence senior ETF analyst Eric Balchunas wrote, "Yes, an ETF fixes this," while noting that some self-custody advocates dismiss the funds as "paper bitcoin" and questioning whether a reportedly small hardware-wallet company should protect life-changing sums. U.S. markets were closed when he posted the weekend comments, leaving no verified post-comment fund-flow reaction. Kraken chief security officer Nick Percoco called the incident a "wake-up call for the entire hardware wallet industry," and CryptoRank said in a Thursday X post that "July showed that even cold storage does not eliminate technological risks, which can put thousands of wallets at risk simultaneously."
Hackers stole $247.4 million in crypto in July, the most this year after the $644 million stolen in April, according to DefiLlama data, with DefiLlama's hack tracker estimating losses tied to the Coldcard exploit at $115 million. Canadian coach Jonathan Goodman said in a post on X that 18.25 $BTC, worth about $1.6 million Canadian, was swept from his device on July 29.
Mentioned Coins
Share Article
Quick Info
Disclaimer: This content is for information and entertainment purposes only. It does not constitute financial, investment, legal, or tax advice. Always do your own research and consult with qualified professionals before making any financial decisions.
See our Terms of Service, Privacy Policy, and Editorial Policy.