Monitor this situation.
Unsubscribe anytime.
[SITUATION] · [ACTIVE] · [TECHNOLOGY]
13 clusters · 54 sources · 53 days · First seen · Last updated
Bitcoin ecosystem security vulnerabilities and Coldcard hack
Overview
The Bitcoin ecosystem has faced significant security challenges stemming from widespread vulnerabilities in software and hardware. Research identified nearly 5,000 high-risk or critical flaws across various applications, including wallets, node software, mining pools, and exchanges. A notable weakness was found in the CryptoJS JavaScript library, where a reliance on Math.random led to a $5.7 million loss affecting 2,114 addresses.
A critical focus involves entropy failures in hardware wallets. A firmware error in Coldcard devices (specifically Mk2, Mk3, Mk4, Q, and Mk5 models) dating back to March 2021 caused devices to use a predictable software-based pseudo-random number generator instead of a true hardware random number generator. This flaw reduced cryptographic security from 128 bits to as low as 32 or 40 bits, allowing attackers to reconstruct seeds through brute-force attacks. In response, Coldcard released critical firmware updates, but warned that these will not repair existing, compromised seed phrases. Exploitation of this flaw has resulted in the theft of over 2,000 Bitcoin, valued at more than $100 million.
Recent developments involve white-hat hackers moving 52.37 BTC, valued at over $4.5 million, into a recovery address associated with the Wyoming-based Crypto Recovery Trust. This action aims to secure funds from the Coldcard exploit before they can be stolen by malicious actors. The recovered Bitcoin represents approximately 2.8% of the total funds linked to the exploit, with total losses estimated between $100 million and $154 million. Victims of the exploit are now pursuing legal recourse.
Entities
Coldcard · Galaxy Research · Coinkite · Bitcoin · Crypto Recovery Trust
Claims
What the coverage asserts, and how many sources carry each claim.
Coverage disagrees
Sources make claims that cannot both be true. CLSTR reports the disagreement; it does not decide who is right.
-
"A total of 1,778.58 Bitcoin were swept from 8,680 addresses since July 30, 2026."
vs
"Attackers drained approximately 1,596 BTC across more than 5,200 addresses in three confirmed waves."
These claims provide different totals for both the amount of Bitcoin swept (1,778.58 vs 1,596) and the number of addresses involved (8,680 vs 5,200).
-
"A total of 1,778.58 Bitcoin were swept from 8,680 addresses since July 30, 2026."
vs
"Approximately 1,596 Bitcoin, valued at over $100 million, were stolen from roughly 7,300 addresses."
These claims provide different totals for both the amount of Bitcoin swept (1,778.58 vs 1,596) and the number of addresses involved (8,680 vs 7,300).
-
"Approximately 1,596 Bitcoin, valued at over $100 million, were stolen from roughly 7,300 addresses."
vs
"Attackers drained approximately 1,596 BTC across more than 5,200 addresses in three confirmed waves."
These claims provide different counts for the number of addresses involved (5,200 vs 7,300).
-
"The Mk4, Q, and Mk5 devices produced seeds with only 72 bits of entropy instead of the intended 128 bits."
vs
"The vulnerability reduced cryptographic security from 128 bits to approximately 40 bits."
The claims assert different levels of reduced security/entropy (40 bits vs 72 bits).
- [DISPUTED] The vulnerability reduced cryptographic security from 128 bits to approximately 40 bits.
- [DISPUTED] A total of 1,778.58 Bitcoin were swept from 8,680 addresses since July 30, 2026.
- [DISPUTED] Attackers drained approximately 1,596 BTC across more than 5,200 addresses in three confirmed waves.
- [DISPUTED] Approximately 1,596 Bitcoin, valued at over $100 million, were stolen from roughly 7,300 addresses.
- [DISPUTED] The Mk4, Q, and Mk5 devices produced seeds with only 72 bits of entropy instead of the intended 128 bits.
- [● 5 SOURCES] A firmware bug introduced in March 2021 caused key generation to use a weak software random number generator instead of hardware entropy.
- [● 3 SOURCES] On-chain data shows 233,000 BTC left long-term holder wallets following the breach.
- [● 3 SOURCES] A firmware vulnerability in Coldcard devices caused predictable seed phrase generation.
- [● 3 SOURCES] Installing the new firmware does not repair seed phrases that were created using the affected software versions.
- [● 3 SOURCES] Users with affected seed phrases must create new wallets and transfer their Bitcoin to the new addresses.
- [● 2 SOURCES] Coinkite advised users on firmware versions 4.0.1 through 4.1.9 to migrate funds immediately due to compromise risk.
- [● 2 SOURCES] Some of the Bitcoin moved to safety came from Ledger and Trezor users rather than Coldcard owners.
Timeline
-
2 days ago
[TECHNOLOGY] 2 sourcesCryptocurrency security incidents target fake bridges and trusted hardwareCryptocurrency users face diverse security threats, ranging from a $2 million fake GIWA bridge scam to major exploits involving Coldcard hardware wallets and the Liquid Network sidechain.
-
5 days ago
[TECHNOLOGY] 2 sourcesColdcard exploit victims pursue legal action against CoinkiteVictims of the Coldcard hardware wallet exploit are pursuing legal action against Coinkite, while white-hat hackers have successfully recovered approximately 52 BTC for a recovery trust.
-
8 days ago
[TECHNOLOGY] 10 sourcesWhite-hat hackers move 52 BTC to Coldcard recovery trustWhite-hat hackers have secured 52.37 BTC from the Coldcard hardware wallet exploit, moving the funds to the Crypto Recovery Trust to facilitate reimbursement for verified victims.
-
22 days ago
[TECHNOLOGY] 5 sourcesColdcard wallet hack: Attacker moves 45% of stolen BitcoinHackers behind the Coldcard wallet exploit have moved 45% of stolen third-wave Bitcoin using THORChain and CoinJoin to obscure the trail. The breach was caused by a 2021 firmware vulnerability.
-
30 days ago
[TECHNOLOGY] 2 sourcesColdcard hardware wallet flaw leads to $100 million Bitcoin theftA firmware flaw in Coldcard hardware wallets compromised cryptographic entropy, allowing hackers to steal over 2,000 Bitcoins worth more than $100 million without physical device access.
-
about 1 month ago
[TECHNOLOGY] 6 sourcesColdcard hack: 87% of stolen Bitcoin remains unmovedGalaxy Research reports that 87.3% of the Bitcoin stolen in the Coldcard hardware wallet hack, valued at over $114 million at the time of theft, remains unmoved in attacker-controlled addresses.
-
about 1 month ago
[TECHNOLOGY] 2 sourcesCoinkite updates Coldcard firmware following seed generation vulnerabilityCoinkite released firmware updates for Coldcard hardware wallets to fix a seed generation flaw that reportedly led to losses of over $112 million in Bitcoin. Users are urged to generate new seeds.
-
about 1 month ago
[TECHNOLOGY] 13 sourcesColdcard issues firmware fix after major Bitcoin seed vulnerabilityCoinkite has released firmware updates for Coldcard wallets following a seed-generation flaw that led to over $112 million in Bitcoin thefts. Users must generate new seeds to secure funds.
-
about 1 month ago
[TECHNOLOGY] 3 sourcesColdcard releases firmware updates following Bitcoin seed vulnerabilityColdcard released firmware updates for Mk4, Mk5, and Q devices to fix a seed generation flaw that led to over $100 million in Bitcoin theft. Affected users must migrate to new wallets.
-
about 1 month ago
[TECHNOLOGY] 8 sourcesHardware wallets face dual threats from firmware flaws and data breachesHardware wallet users face massive risks as a Coldcard firmware flaw leads to $115M in Bitcoin theft, while data breaches at shipping partners expose customer addresses to physical 'wrench attacks'.
-
about 2 months ago
[TECHNOLOGY] 12 sourcesColdcard firmware flaw leads to $116M+ Bitcoin theftA firmware flaw in Coldcard hardware wallets, reducing entropy to 40 bits, has resulted in the theft of over $116 million in Bitcoin, prompting a massive migration of funds by long-term holders.
-
about 2 months ago
[TECHNOLOGY] 6 sourcesColdcard firmware flaw leads to massive Bitcoin seed theftsA firmware error in Coldcard hardware wallets has enabled the theft of up to 2,055 BTC, totaling nearly $130 million, due to predictable seed generation. Users are advised to migrate wallets immediately.
-
about 2 months ago
[TECHNOLOGY] 5 sourcesBitcoin ecosystem reveals hundreds of critical security bugsResearchers found 85 critical and 635 high‑risk bugs in Bitcoin software, plus over 1,000 high‑severity issues, a CryptoJS flaw causing $5.7 M loss, and a Coldcard seed‑entropy bug, highlighting widespread risk
Sources
belgiannature.be · bitcoinbasis.de · bitcoinethereumnews.com · bitcoinmagazine.com · biz.heraldcorp.com · blockchainreporter.net · blockmedia.co.kr · blockonomi.com · blocktempo.com · blogspan.net · btc-echo.de · cahighways.org · coindeskjapan.com · coinedition.com · cointelegraph.com · confirmado.net · countryrebel.com · crypto-insiders.nl · crypto-times.jp · crypto.news · cryptobreaking.com · cryptobriefing.com · cryptonomist.ch · cryptoslate.com · cryptoticker.io · culturacolectiva.com · decrypt.co · detlionblood32.wordpress.com · dev.to · dnyuz.com · ebizlatam.com · economytoday.sigmalive.com · en.bitcoinsistemi.com · gizmodo.com · it-boltwise.de · journalducoin.com · koinbulteni.com · kryptomagazin.cz · mobilecrunch.com · naturalis.hu · neweconomy.jp · newmoney.gr · news-krypto.de · news.bitcoin.com · news.heraldcorp.com · newsbit.nl · perfil.com · phocapblockchain.net
This summary has been updated 18 times: see revision history