Loading prices…
🩸BEARISH

Coldcard entropy bug drains 600 BTC from dormant wallets

Roughly $38M has been swept from single-sig seeds generated between 2021 and 2023, and the exploit is unpatchable by design: any firmware fix would tip off attackers to wallets still holding funds.

Roughly 600 BTC, worth about $38 million, has been drained from dormant single-sig Bitcoin wallets generated on Coldcard hardware between 2021 and 2023, after an entropy bug in the device's seed generation code was exploited in the open. The flaw traces to a 2021 firmware rewrite: Coldcard's safety check confirmed only that a true-randomness setting existed in code, not that it was actually enabled, so seeds were derived from predictable, guessable input.

Why it matters

Coldcard built its reputation as the cold-storage pick of the Bitcoin OG / maxi community, the device every hardcore self-custody user swore by. A vulnerability sitting silently in firmware since 2021 undermines the assumption that air-gapped hardware is automatically the safest tier of custody. Other hardware wallets (Ledger, Trezor and the rest) are not affected by this specific bug, but the incident reframes the conversation around how supply-chain firmware changes get audited.

Market impact

The exploit is structurally unpatchable. Patching firmware does not retroactively fix the vulnerable seeds already generated, and any public disclosure instantly flags the at-risk wallets to professional attackers who can start sweeping them in bulk. The only partial mitigations available to victims are practices like dice-rolled entropy, passphrases or multisig setups that the seed-generation step never touched. The Bitcoin price reaction today is being driven less by the hack itself, which affects a thin slice of self-custody users, and more by macro pressure: the US 30-year yield has climbed to 5.27%, its highest level since June 2007, and the Clarity Act appears stalled in Congress even as Circle secured a New York limited purpose trust charter for USDC. Self-custody evangelists are urging affected users to move funds to multisig or to an exchange temporarily, while professional sweepers are now racing the original, reportedly AI-assisted, attacker to the remaining exposed balances.

Related tokens
$BTC

Frequently asked questions

  1. What is the Coldcard entropy bug and when did it start?

    A 2021 Coldcard firmware rewrite introduced a safety check that confirmed a true-randomness setting existed in code, but did not verify it was actually enabled. Seeds generated on affected firmware between 2021 and 2023 were derived from predictable input and can be brute-forced.

  2. How much Bitcoin has been stolen so far?

    Roughly 600 BTC, worth about $38 million, has been swept from dormant single-sig wallets generated on Coldcard hardware during the affected window, according to the early on-chain tally.

  3. Are Ledger and Trezor wallets affected?

    No. The bug is specific to Coldcard's seed-generation code. Ledger, Trezor and other hardware wallet vendors are not impacted by this particular vulnerability.

  4. Can Coldcard fix the bug with a firmware patch?

    No. A firmware update would not retroactively repair seeds already generated, and any public disclosure would immediately tip off attackers to the remaining vulnerable wallets. The only partial mitigations are practices the seed-generation step never touched: dice-rolled entropy, passphrases or multisig setups.

  5. What should affected Coldcard users do right now?

    Users who generated a single-key wallet on Coldcard between 2021 and 2023 without dice-rolled entropy, a passphrase or multisig should move funds immediately, to a multisig setup if they have one configured, or temporarily to a regulated exchange, before professional sweepers start cleaning out the remaining exposed…

Source attribution
Aggregated from Altcoin Daily · Verified · Last refreshed 1h ago
Open original →
Original content