Coldcard Losses Could Top $151 Million in Bitcoin

Coldcard losses shown as loaded dice on a gaping safe emptied of its bitcoin

Galaxy Research puts confirmed Coldcard losses at 1,778 BTC stolen, roughly $112M, in the exploitation of the manufacturer’s entropy flaw. A suspected fourth wave would lift the total to 2,417 BTC, close to $151.3M. The attackers have not moved since August 6. More than 190 victims have been contacted directly, and most of the haul is still sitting untouched.

Key Takeaways

  • 1,778 BTC are confirmed stolen, with a fourth wave that would push the total to 2,417 BTC.
  • A March 2021 firmware cut seed generation entropy to 40 bits on some models.
  • Roughly 1,531 BTC still sit on attacker addresses, while 246 BTC have been laundered.

Forty Bits of Entropy Instead of a Hundred and Twenty-Eight

The flaw is not a backdoor, it is a failure of randomness. The hardware entropy source stopped contributing to seed creation in certain firmware builds, leaving the job to a far more predictable software generator.

The consequence is blunt and countable. A seed meant to rest on 128 bits of entropy dropped to about 40 bits on Mk2 and Mk3 units running versions 4.0.1 through 4.1.9. A 40-bit search space falls to ordinary hardware. That mechanism is what allowed $70M in bitcoin to vanish in forty-one minutes.

The manufacturer laid out the exact scope. The security advisory published by Coinkite states that Mk4, Q and Mk5 units predating the fixed releases land around 72 bits, a degraded level but far less exposed than the 40 bits of earlier generations.

The root cause traces back to a plumbing change. The manufacturer’s technical breakdown of the incident points to Yasmarang, the pseudo-random generator built into MicroPython since May 2018, which slipped into the seed generation path during a library migration in March 2021. Five years passed before anyone noticed.

One group of users escapes the problem entirely. Anyone who entered at least 50 independent, private dice rolls when creating a seed contributed 128 bits of entropy on that input alone. At 99 rolls, the contribution climbs to roughly 256 bits.

The attack method follows mechanically from those numbers. Attackers reconstructed seeds from device serial numbers and clock states, then swept the funds without ever physically touching a single unit.


Coldcard losses
Advertisement – investing involves risk.

The Attack Waves Dried Up on August 6

The timeline is tight. Exploitation started on July 30, 2026, and the last confirmed attacker activity dates to August 6. Nothing has been detected since.

The shockwave reaches well past those affected. Roughly $15B in bitcoin has been shifted to custody arrangements deemed safer, and rival manufacturers report a phishing surge feeding on the panic. The sequence echoes the leak of 13,689 Trezor customer addresses days later.

Galaxy Research offers two readings of that stop without picking one. Either vulnerable users migrated their funds in time, or most of what could be drained already has been. Both lead to the same observable outcome, with very different implications for anyone who has not moved yet.

What happened to the haul is unusual. Around 1,531 BTC have not budged from attacker-controlled addresses, while only 246 BTC were moved, close to two thirds of that through mixing services. Sitting on a sum like that suggests either caution about on-chain tracing or genuine difficulty offloading the volume.

The victim count remains provisional. More than 190 people have been contacted directly by analysts, a figure that covers only the cases identified and documented at this stage of the investigation.

Self-custody makes that number hard to close. There is no institution holding a client list to notify, so every victim has to notice the loss and then choose to report it. The real figure is therefore a floor rather than a total.

Final Coldcard losses therefore hang on two open unknowns: confirmation of the fourth wave, and the number of victims who have not come forward yet. The gap between $112M and $151.3M sits entirely inside that grey zone.


Also on Cryptonomic:


What a Coldcard Owner Should Do Right Now

The guidance from analysts allows no nuance. Anyone holding a single-signature Coldcard wallet should move funds to fresh addresses immediately, including where no suspicious movement has appeared.

The reason sits in the nature of the vulnerability. A weak seed cannot be repaired by an update, because the secret itself was badly drawn at creation. Installing the fixed firmware, available as version 4.2.0 for Mk2 and Mk3, protects future seeds and leaves old ones exactly as exposed as before.

Multisignature changes the equation completely. A setup requiring several independent keys stays protected even if one seed is reconstructed, which is why the recommendation names single-signature configurations specifically. The lesson runs past hardware alone, as it did when a BTCPay Server flaw drained Lightning nodes.

Further out, the episode moves the sector’s fault line. Hardware wallets were sold for a decade as the definitive answer to custody risk. They have just shown that the promise rests on a link invisible to the buyer, the quality of the randomness produced in the device’s first second of life.

Auditability becomes the next battleground. A buyer can verify a firmware signature, but cannot verify that the hardware generator actually fed the seed. Fund movements tracked this year, such as 90 wallets climbing past 10,000 BTC, run on devices nobody audits at that level.

The quiet since August 6 therefore guarantees nothing. A weak seed stays weak forever, and nothing forces an attacker to spend what they have already computed.

The final tally of Coldcard losses will be measured in months, not in the two weeks since exploitation began. Seeds already computed but not yet swept form a dormant stock nobody can size, including the analysts who have tracked the case since July 30.

Insurance and custody providers will draw their own conclusions from that. A risk that cannot be closed by a patch, only by migrating funds, changes how a self-custody setup gets priced, and it hands regulated custodians an argument they did not have to build themselves.

Follow the story on Cryptonomic.

Comments

No comments yet. Why don’t you start the discussion?

    Leave a Reply

    Your email address will not be published. Required fields are marked *