Full story
Coldcard seed flaw exploited
Galaxy Research said a Coldcard hardware wallet vulnerability tied to a March 2021 firmware release enabled attackers to drain bitcoin from thousands of wallets, with losses near $89 million and a third wave of sweeps spreading to 4,500 addresses.
“losses near $89 million”
Reuters-aligned reporting in the same incident described an attacker draining 1,196 Bitcoin addresses in 41 minutes on July 30, taking 1,082.65 BTC worth about $70.2 million at the time.

The Hacker News said the March 2021 integration error routed seed generation to a deterministic software pseudorandom number generator instead of the STM32 hardware random number generator, letting an attacker reproduce candidate output streams offline.
Galaxy Research flagged that three distinct waves swept 1,367 bitcoin—nearly $89 million at recent prices—from 4,585 addresses, with the latest wave targeting smaller balances and using more complex, harder-to-trace transaction patterns.
The Hacker News added that Coinkite shipped emergency firmware for every affected model and release track on July 31, but installing it does not repair an existing seed.
Galaxy mapping and warnings
Galaxy Research said it identified 1,196 addresses involved in transactions tied to the July 30 sweep, tracing activity between 1:10 AM and 1:51 AM UTC across blocks 960,183 to 960,191.
The Hacker News reported that Block traced the fault to Coldcard's production config, defining MICROPY_HW_ENABLE_RNG as zero because Coinkite supplies its own hardware-RNG wrapper.

Galaxy Research said the transactions share a recognizable on-chain pattern, including identical 30 satoshis per virtual byte fees and the absence of change outputs, while warning that later attacks may not reuse the same fingerprint.
Changpeng Zhao warned that “Even hardware wallets can have bugs,” and advised holders to split funds among several wallets.
Coinkite co-founder Rodolfo Novak said the company released a hotfix intended to remove the software fallback path, but warned that installing the fix does not retroactively protect seeds generated on vulnerable firmware.
What users must do next
Coinkite told users that if their seeds were created using vulnerable firmware, they must move their coins to a new seed, because “Restoring the old seed to updated firmware or another wallet carries the weakness forward.”
“Restoring the old seed to updated firmware or another wallet carries the weakness forward.”
The Hacker News said Coinkite estimates effective entropy at roughly 40 bits on the Mk3 and about 72 bits on the Mk4, Mk5 and Q, against 128 bits for a 12-word BIP-39 seed.
Galaxy Research cautioned that future attacks targeting Coldcard-generated addresses may not always follow the same on-chain “fingerprint,” meaning wallet owners should not assume the first identifiable traits will be reused.
The Hacker News said Coinkite stated a seed built with at least 50 fair, independent, private dice rolls is not at risk from this bug alone, while other affected users should migrate.
The Hacker News also noted that multisig helps only when the quorum is not built entirely from affected devices, and that TAPSIGNER, OPENDIME and SATSCARD use different codebases and are unaffected.



