< Back to all clusters
[TECHNOLOGY] · 26 sources

Coldcard wallet exploit drains $88 million from 4,585 Bitcoin addresses

A firmware flaw in Coldcard hardware wallets released in March 2021 caused seed phrases to be generated with insufficient randomness, making private keys guessable. The bug affected multiple models (Mk2, Mk3, Mk4, Mk5 and Q). Galaxy Research identified three coordinated attack waves that have swept 1,367.05 BTC – roughly $88‑$89 million – from 4,585 addresses. The first two waves moved funds to a small set of shared P2WPKH collection addresses; the third wave used separate P2WSH destinations, averaging 6.37 victim addresses per transaction and draining 207.73 BTC from 1,912 wallets. Most of the stolen coins remain unspent, with the attacker controlling about 1,366 BTC. Victims, many of whom are long‑term holders (average dormancy ≈ 3.2 years), are moving Bitcoin to centralized exchanges, triggering a spike in sub‑1 BTC transactions. Researchers warn that every single‑signature Coldcard address created after the March 2021 firmware update is at risk and advise users to migrate funds to new wallets with fresh seeds.

Entities: Alex Thorn · Bitcoin · Coinkite · Coldcard · Coldcard hardware wallet · Galaxy Research

Claims

What the coverage asserts, and how well corroborated each claim is across sources.

  • [○ 1 SOURCE] The flaw affected Coldcard models Mk2, Mk3, Mk4, Mk5 and Q. (Coinkite product advisory)
  • [● 3 SOURCES] The stolen Bitcoin remains largely unspent; the attacker controls about 1,366 BTC. (On‑chain tracking by Galaxy Research and others)
  • [● 3 SOURCES] Researchers warned that every single‑signature Coldcard address created after the March 2021 firmware update is at risk and should be moved. (Galaxy Research alerts)
  • [● 3 SOURCES] Victims moved Bitcoin to exchanges, causing a spike of about 39,600 BTC in sub‑1 BTC transactions in a single day. (CryptoQuant data cited in multiple reports)
  • [● 4 SOURCES] The third wave drained 207.7294 BTC from 1,912 addresses, used P2WSH destinations and averaged 6.37 victim addresses per transaction. (Galaxy Research wave‑3 analysis)
  • [● 3 SOURCES] A March 2021 firmware flaw in Coldcard devices reduced seed entropy, making private keys guessable. (Galaxy Research, Coinkite disclosures)
  • [● 4 SOURCES] A total of 1,367.05 BTC (about $88‑$89 million) was stolen from 4,585 addresses. (Galaxy Research totals)
  • [● 4 SOURCES] Galaxy Research identified three attack waves targeting Coldcard‑generated addresses. (Galaxy Research analysis)

Sources

about 5 hours ago
about 7 hours ago
about 8 hours ago
about 16 hours ago