Investing

Coldcard Flaw Blamed for $38 Million Bitcoin Theft From 500…

How Did The Coldcard Attack Drain 594 Bitcoin?

Roughly 594 bitcoin worth about $38 million was removed from around 500 wallets early Friday in an attack linked to weak key generation in certain Coldcard hardware wallet firmware versions.

The theft occurred between 01:31 and 01:56 UTC, with the attacker moving 1,324 portions of bitcoin across 500 transactions within three Bitcoin blocks. About 562 BTC was later consolidated into a single address that had not moved at the time of reporting.

Every drained wallet used a single-signature setup and held more than 0.15 BTC. Many of the wallets had remained inactive for years, while the stolen coins dated from 2021 through 2026, closely matching the period during which the vulnerable firmware was available.

Bitcoin continued trading above $64,000 during early Asian hours, suggesting that the theft had little immediate effect on the wider market. The incident instead created a direct security risk for Coldcard users whose wallet seeds were generated with affected firmware.

What Went Wrong With Coldcard’s Key Generation?

Coldcard is a bitcoin-only hardware wallet produced by Canadian manufacturer Coinkite. Its Mk2, Mk3, Mk4, Q and Mk5 devices are separate generations designed to create and store private keys away from internet-connected computers.

A wallet seed should be generated from enough random information that an attacker cannot realistically recreate it. Block’s Bitcoin engineering and security teams found that a firmware build setting caused affected Coldcard devices to bypass their hardware random-number generator.

A supporting software library checked only whether that setting existed, rather than whether it was enabled. The device then relied on a weaker software substitute seeded with the chip’s serial number and internal clock registers.

Those inputs are not secret. A serial number is fixed device metadata, while clock values can potentially be narrowed down through timing analysis or testing on similar hardware. An attacker able to reconstruct those inputs could reduce the number of possible wallet seeds enough to identify vulnerable addresses and steal the funds.

The change was traced to code dated March 1, 2021, and was introduced in firmware released that month. Exposure depends on the firmware running when the wallet seed was created, not when the Coldcard device was purchased or whether the seed was later imported into another wallet.

Investor Takeaway

Updating the device does not repair a seed that was generated with weak randomness. Affected users need to create a new seed with fixed software and move their bitcoin to addresses controlled by that new seed.

Which Coldcard Users May Still Be Exposed?

Coinkite initially warned users who created seeds on an Mk3 running firmware version 4.0.1 or later. Early analysis said Mk4, Q and Mk5 devices were not affected, but later guidance warned that seeds generated on those models before the relevant firmware fixes may also face risk.

Both Coinkite and Block described their findings as preliminary. Block said it disclosed the issue to Coinkite and published before completing full exploitability testing because wallet draining was already taking place.

The problem may extend beyond standard recovery phrases. The same weak generator was reportedly used for Coldcard paper-wallet private keys, seed-splitting masks, device-cloning keys and Key Teleport transfers. Paper wallets may face greater exposure because the generated output can become the private key directly without another derivation step.

Users who imported a vulnerable Coldcard seed into another hardware or software wallet remain exposed. Moving the same seed to a Trezor, Blockstream, Foundation, Tangem or another device does not create new private keys. Funds remain controlled by the original compromised seed until they are sent to a newly generated wallet.

What Does The Theft Mean For Hardware Wallet Security?

The attack shows that keeping keys offline cannot protect funds when the keys themselves were created with predictable inputs. Hardware wallets reduce exposure to malware and remote theft, but their security still depends on correct firmware, trustworthy random-number generation and careful review of cryptographic code.

Coinkite said it had been unaware of the bug and suggested that an attacker may have used an advanced artificial intelligence model to examine older open-source firmware. There is no public evidence confirming that AI was used, and the company also acknowledged that its own recent AI-assisted review did not detect the flaw.

The incident may increase scrutiny of open-source hardware wallet code, software build settings and independent security audits. It also strengthens the case for multisignature storage when holding large amounts of bitcoin.

A multisignature wallet can require two of three separate keys to approve a transaction. Using devices from different manufacturers reduces the chance that one firmware defect will expose every key needed to move the funds.

Coldcard users now face two questions: whether their seed was created with affected firmware and whether the attacker is still identifying vulnerable wallets. The confirmed theft has stopped moving for now, but unchanged funds remain at risk if their private keys were generated through the same flawed process.

© 2026 Michaels Finance Corner. All rights reserved.