Bitcoin holders bought Coldcard wallets to keep their money away from hackers. But a flaw buried inside some devices made the secret keys protecting those coins far easier to predict — and attackers appear to have exploited it on a massive scale.
For years, one of the strongest pieces of advice in crypto was simple:
- Take your Bitcoin off the exchange.
- Put it in a hardware wallet.
- Keep it offline.
For hundreds of Coldcard users, that was exactly what they did.
Then the Bitcoin started disappearing.
An attacker swept roughly 594 Bitcoin from around 500 wallets in less than half an hour during an initial wave on July 30, according to CoinDesk.
Investigators later linked far more wallets and Bitcoin to the same underlying weakness.
By the time the incident had expanded, the total connected to the exploit was estimated at about $88.6 million.
The most unsettling part was how little the attacker apparently needed from the victims.
- No stolen wallet.
- No password handed over.
- No phishing page.
- No physical access.
- The weakness had already been created years earlier.
THE PROBLEM WAS INSIDE THE KEY

Coldcard is a Bitcoin-only hardware wallet made by Canadian company Coinkite.
Its purpose is straightforward: keep the private keys needed to spend Bitcoin away from internet-connected devices.
But those keys have to begin somewhere.
When a new wallet is created, the device generates a recovery seed using random data. That seed can then be used to derive the private keys controlling the Bitcoin.
The security of the entire process depends on one thing:
The randomness must actually be random.
In certain Coldcard firmware versions, it was not random enough.
CoinDesk reported that the vulnerability caused affected devices to bypass the intended hardware random-number generator and fall back to software-generated data based partly on information that was not secret.
Coinkite later acknowledged that seeds produced on affected firmware could be at risk and urged users to move funds where necessary.
- To the owner, nothing necessarily looked wrong.
- The wallet still worked.
- The PIN still worked.
- The Bitcoin still appeared where it should.
But the mathematical secret protecting it could be far easier to guess than anyone realised.
THE ATTACKER DIDN’T NEED THE WALLET

That distinction changes everything.
Breaking Bitcoin itself is effectively out of reach with current computing.
Trying every possible correctly generated private key would take an absurd amount of computing power.
But if a faulty device generates keys from a much smaller set of possibilities, the attacker no longer has to search the entire universe.
- The search becomes smaller.
- Still difficult.
- But possible.
An attacker could generate huge numbers of candidate seeds, derive the Bitcoin addresses they would produce and compare those addresses with the public blockchain.
If one matched an address containing funds, the attacker had found something far more valuable than the physical wallet.
The key.
That is why a Coldcard could be sitting quietly in a drawer, disconnected from the internet, while the Bitcoin it controlled was still vulnerable.
The device was offline.
The weakness wasn’t.
THEN CAME THE SWEEP

Once vulnerable wallets had apparently been identified, the theft moved fast.
CoinDesk reported that the first major sweep took around 25 minutes, removing roughly 594 BTC from about 500 wallets.
Subsequent analysis widened the scope.
A later CoinDesk report cited Galaxy Research estimates of more than 1,082 Bitcoin taken from 1,196 addresses, worth around $70 million at that stage.
BleepingComputer subsequently reported that the total associated with the compromised wallets had reached an estimated $88.6 million.
The figures changed as researchers identified additional addresses and Bitcoin’s price moved.
But the basic story did not.
Wallets designed specifically to reduce hacking risk had generated secrets that were not as secret as they were supposed to be.
SOME OF THE BITCOIN HAD BEEN SITTING FOR YEARS
Another detail made the incident particularly striking.
Many of the affected wallets had apparently been dormant for long periods.
They were not accounts constantly sending money through exchanges.
They were the kind of wallets people often use precisely because they intend to hold Bitcoin for years.
That is supposed to be one of hardware wallets’ biggest advantages.
- Buy.
- Store.
- Disconnect.
- Wait.
But a wallet that contains a weak recovery seed does not become safer simply because nobody touches it.
Time can actually give an attacker more opportunity to work.
COINKITE ISSUED A WARNING
Coinkite published a security advisory after the attacks became public.
The company warned that funds controlled by seeds generated on affected Coldcard firmware could be at risk.
Users with potentially vulnerable wallets were advised to migrate funds to a newly generated seed on unaffected hardware or firmware.
That detail is crucial.
Updating the software does not automatically fix a recovery seed that was already created with insufficient randomness.
The old seed remains the old seed.
If an attacker can reconstruct it, installing new firmware afterwards cannot make the original secret stronger.
The safest response is to create a new secure seed and move the Bitcoin.
NOT EVERY COLDCARD USER WAS EQUALLY EXPOSED
Coinkite has also stressed that the risk depends on how a wallet was originally created and used.
Its advisory says users who protected affected seeds with a sufficiently strong BIP-39 passphrase faced substantially lower risk from this specific weakness.
That is different from the PIN used to unlock the physical device.
The distinction matters because cryptocurrency security often contains multiple layers that ordinary users may assume are interchangeable when they are not.
- A hardware wallet is one layer.
- The recovery seed is another.
- A passphrase can be another.
The failure of one layer can suddenly make the others far more important.
THE BIGGER LESSON FOR BITCOIN HOLDERS
The Coldcard incident does not mean hardware wallets are inherently unsafe.
Nor does it mean Bitcoin’s underlying cryptography was broken.
The failure occurred in the process used by certain devices to create the secrets protecting the Bitcoin.
But that still leaves an uncomfortable lesson.
Crypto users often frame security as a choice between two options:
- Trust an exchange.
- Or trust yourself.
- Reality is more complicated.
- Self-custody means trusting the hardware.
- The firmware.
- The software libraries.
- The random-number generator.
- Your backups.
- Your passphrase.
And your own ability to use all of them correctly.
If any one of those layers fails, there may be no bank to telephone.
No card company to reverse the payment.
No fraud department capable of freezing the transfer.
THE BITCOIN NETWORK DID EXACTLY WHAT IT WAS TOLD
Bitcoin does not know who legally owns a wallet.
It does not know whether a private key was stolen.
It does not know whether the person signing a transaction is the person who originally bought the coins.
It checks the signature.
If the signature is valid, the Bitcoin moves.
That is part of what makes the system powerful.
It is also what makes a compromised private key so dangerous.
Once the attacker possesses the right key, the network does not see a thief.
It sees an authorised transaction.
And that is perhaps the most uncomfortable part of the Coldcard story.
The wallets were bought because their owners wanted control.
They wanted their Bitcoin away from exchanges and safely in their own hands.
But control over Bitcoin ultimately belongs to whoever controls the private key.
For some Coldcard users, the physical wallet never left their possession.
Their Bitcoin did.

