Coldcard Firmware Bug Enables $89 Million Bitcoin Theft; Binance Founder Warns Users
The vulnerability, introduced in firmware released in March 2021, caused the seed‑generation routine to fall back to a deterministic software pseudo‑random number generator instead of the STM32 microcontroller’s hardware random‑number generator. The change cut the effective entropy of the 128‑bit seed to about 40 bits, making private keys vulnerable to brute‑force attacks.
Galaxy Research identified three distinct theft waves that began on July 30 and continued through August 1. The first wave saw 1,082.65 BTC withdrawn from 1,195 addresses in a 41‑minute burst. The second wave took 76.16 BTC from 1,478 addresses. The third wave, running from 12:23 UTC on July 31 to 06:42 UTC on August 1, moved 207.73 BTC from 1,912 addresses. Median losses fell from 0.270 BTC in wave one to 0.010 BTC in wave two and 0.013 BTC in wave three, indicating the attacker shifted focus to smaller balances as the vulnerable key space depleted.
During the first two waves, stolen coins were funneled through a handful of shared collector addresses and then consolidated into a small number of visible P2WPKH holding wallets. In the third wave, the attacker abandoned that pattern; each victim’s coins were sent to a unique destination and now sit in 293 separate P2WSH vaults, which hide spending conditions until the first movement. The sweeper batched an average of 6.37 victims per transaction, used only the default derivation path, and varied the fee constant—30 sat/vB in wave one, 50 and 10 in wave two, and roughly 200 then exactly 10 in wave three.
Coinkite, the Canadian firm that designs Coldcard wallets, issued an advisory on Friday acknowledging responsibility for the firmware bug. The company released emergency hotfixes for the affected firmware tracks (Mk3, Mk4, Mk5, and Q). Coinkite’s co‑founder Rodolfo Novak posted on X that the update does not protect seeds that were already created on vulnerable firmware, urging users who generated seeds with the affected firmware to move their funds to a new seed.
Galaxy Research notes that the stolen Bitcoin was consolidated within minutes into a handful of addresses and has not moved since. The pattern of identical hard‑coded fees and the absence of change outputs suggest the attacker used an automated tool that spent keys it already held, rather than owners moving their own funds.
In a post on X on Saturday, Binance founder Changpeng “CZ” Zhao warned that even hardware wallets are not fail‑proof. “Nothing is 100%,” he wrote, citing the Coldcard exploit that drained roughly $70 million in a 41‑minute sweep. Zhao advised holders to spread their funds across several wallets to reduce exposure, while acknowledging that no setup is entirely foolproof. He closed with the familiar admonition, “Stay SAFU!”
The incident underscores that the security of self‑custody solutions hinges on firmware integrity and the randomness used to generate seeds. While the firmware update stops new weak seeds from being created, it does not repair existing ones, leaving users who have not migrated their funds at risk.
With total losses now close to 1,367 BTC, the theft has spurred a broader discussion about hardware wallet security and the need for ongoing vigilance, even for devices designed to remain offline. The Coldcard firmware bug, the subsequent theft, and the warnings from industry leaders highlight the importance of rigorous testing and rapid response in the rapidly evolving crypto ecosystem.