
Bitcoin Hardware Wallet Flaw Triggers $88 Million in Thefts as Security Experts Warn Attacks Are Still Ongoing
A firmware flaw dating back to 2021 has allowed attackers to steal tens of millions of dollars in Bitcoin from vulnerable hardware wallets, and security researchers warn the campaign may not be over. Anyone who generated a wallet seed on an affected Coldcard device is being urged to move their Bitcoin immediately to a newly created wallet rather than simply installing updated firmware.
Researchers at Galaxy Research traced the first coordinated attack to July 30, when 1,196 Bitcoin addresses were drained in just 41 minutes, stealing approximately 1,082.65 BTC worth about $70 million at the time. Additional waves of theft have since pushed the preliminary total to roughly 1,367 BTC—valued at about $88 million—across more than 4,500 addresses, with investigators cautioning that additional compromised wallets may still exist.
The vulnerability originated in firmware released in March 2021. Instead of generating recovery seeds using the hardware wallet’s dedicated random number generator, certain Coldcard firmware versions mistakenly relied on a predictable software-based process, allowing attackers to reproduce wallet seeds offline without ever touching the physical device. Engineers at Block identified the configuration error while investigating the thefts.
Coinkite, the Canadian company behind Coldcard, has acknowledged the flaw. Chief Executive Rodolfo Novak apologized publicly and accepted responsibility for the bug, saying the company’s review process failed to detect the issue before release. Emergency firmware updates have since been issued for affected Mk3, Mk4, Mk5 and Coldcard Q devices.
Installing those updates alone does not protect existing funds. If a wallet’s recovery seed was originally created using vulnerable firmware, the private keys remain compromised even after updating the device. Coinkite instructs affected users to generate an entirely new seed using patched firmware and transfer all Bitcoin to the new wallet. Restoring an older seed simply carries the vulnerability forward. Users who are unsure how their seed was created should migrate to a newly generated wallet regardless.
Not every customer is exposed. Users who added a BIP-39 passphrase or introduced at least 50 dice rolls during setup created additional randomness that attackers cannot reproduce. Tapsigner, Opendime and Satscard use different codebases and are not affected.
Researchers say the most important concern is that the attacks may not be over. Because the vulnerability allows attackers to recreate private keys, any affected wallet that still holds funds could remain a target. On the blockchain, the thefts appear identical to an owner voluntarily moving Bitcoin, making it impossible to determine how many compromised wallets remain.
Curiously, much of the stolen Bitcoin has not yet been moved and remains concentrated in a small number of attacker-controlled addresses. No individual or organization has been publicly identified.
For businesses holding Bitcoin on their balance sheets, the incident demonstrates that hardware wallets alone are not a complete custody strategy. The compromise did not rely on phishing emails, malware or employee mistakes. Instead, it originated from a trusted firmware configuration that remained undiscovered for years before attackers exploited it. Companies that view hardware wallets as the end of the security conversation rather than one layer of a broader custody policy may need to reassess their approach.
Researchers have also noted that advances in AI-assisted code analysis are likely to shorten the time required to uncover dormant software flaws, reducing the window between a bug being introduced and someone discovering it.
Anyone who generated a Bitcoin wallet using an affected Coldcard device should compare their firmware history with Coinkite’s advisory and, if there is any uncertainty, create a brand-new seed using updated firmware and transfer their Bitcoin immediately. Updating firmware without moving funds does not eliminate the underlying risk.
JBizNews Desk | New York
© JBizNews.com All Rights Reserved. Reproduction or distribution without written permission is prohibited.