Coldcard Hardware Wallet Firmware Bug Enables $88 Million Bitcoin Theft
Coldcard, a Bitcoin‑only hardware wallet produced by Canadian company Coinkite, has long been marketed as a secure form of self‑custody. The device contains a dedicated hardware random‑number generator (HRNG) that is intended to provide the entropy required to generate seed phrases. In March 2021, a firmware version released for the Mk2 through Mk5 models included a logic error that caused the wallet to fall back to a deterministic software pseudo‑random generator instead of the HRNG. The bug made the seed phrases predictable, allowing an attacker to guess the private keys without physical access or internet connectivity.
Galaxy Research, a digital‑financial analytics firm, first identified the vulnerability in a series of coordinated sweeps. By Sunday, the firm reported that three distinct waves of attacks had drained 1,367.05 BTC from 4,585 wallets. The total value of the stolen coins was about $88.6 million, based on the market price at the time. On Monday, Galaxy warned of a likely fourth wave that could push losses to 2,055 BTC—approximately $130 million.
Coinkite issued a public warning on Thursday, urging users to update their firmware to a version that corrects the RNG flaw and to move any remaining Bitcoin to new accounts protected by freshly generated seeds. The company’s CEO, Rodolfo Novak, apologized for the oversight and described the situation as a “sober reality of the new AI paradigm.” He added that “AI‑assisted code review can now find latent bugs at a speed that is outpacing even the industry’s most seasoned experts.” Novak also cautioned that any firmware that has been open‑source or publicly available is likely already being examined by both attackers and defenders.
The theft demonstrates that hardware wallets are not immune to software‑based attacks. Unlike centralized exchanges, which can be compromised through phishing, malware, or insider threats, hardware wallets rely on the integrity of their firmware. When that firmware contains a flaw, the device’s security promise is undermined.
Industry observers note that the incident may shift the debate over self‑custody versus custodial solutions. While some commentators argue that the transparency of the blockchain makes it difficult for thieves to launder stolen coins, others point out that the sheer scale of the theft could erode confidence in hardware wallets.
Coinkite has stated that it is taking full responsibility for the bug and is working to ensure that all affected devices receive the necessary firmware update. The company has not yet announced a bounty program or a plan to compensate affected users.
The Coldcard incident underscores the importance of continuous security audits, especially as AI tools become more capable of uncovering subtle code issues. It also serves as a reminder that the security of digital assets depends on both hardware and software integrity.
As of now, the full extent of the losses remains uncertain, and further attacks may still occur. Users of Coldcard devices are advised to update their firmware immediately and to transfer any remaining Bitcoin to new wallets that have not been affected by the flaw.
The incident has prompted calls for more rigorous testing of firmware in hardware wallets and for clearer guidance from manufacturers on how to mitigate similar vulnerabilities in the future.