Loading prices…
🩸BEARISH

Coldcard Exploit Drains $70M in BTC; CZ Urges Wallet Upgrade

The seed-randomness flaw had lurked in firmware since March 2021 and went unnoticed for years, exposing the practical ceiling of single-device self-custody for serious BTC holders.

Coldcard Exploit Drains $70M in BTC; CZ Urges Wallet Upgrade
Coldcard Exploit Drains $70M in BTC; CZ Urges Wallet Upgrade
Coldcard Exploit Drains $70M in BTC; CZ Urges Wallet Upgrade
Coldcard Exploit Drains $70M in BTC; CZ Urges Wallet Upgrade

A flaw in Coldcard hardware wallet firmware dating back to March 2021 allowed an attacker to reconstruct private keys offline and drain roughly $70 million in bitcoin from 1,196 addresses over about 41 minutes on July 30. Galaxy Research's analysis expanded the initial on-chain figure of 594 BTC (about $38M) swept from around 500 wallets, with many affected addresses dormant for years. Coinkite, the maker of Coldcard, has acknowledged the bug and pushed emergency firmware patches, but warns that updating alone does not secure an already-generated vulnerable seed. Users are being told to create entirely new seeds on patched devices and migrate funds carefully.

Why it matters

The breach cuts against the grain of how crypto holders have long thought about self-custody. Hardware wallets are routinely treated as the strongest retail option for cold storage, on the assumption that physical isolation keeps keys safe from remote attack. The Coldcard case shows that assumption is incomplete: a single weakness in seed-generation entropy, undetected for more than four years, was enough to drain nine-figure value without any device ever being touched. Binance founder Changpeng Zhao captured the shift in framing on Saturday, writing that "even hardware wallets can have bugs" and urging holders to split funds across multiple wallets, while acknowledging that diversification carries its own key-management burden.

Market impact

The exploit revives an old debate about the practical ceiling of single-device self-custody for serious BTC balances. The figure puts Coldcard alongside other notable hardware-wallet incidents as a reminder that long shipping histories do not guarantee secure seed generation. Watch for whether competing hardware-wallet vendors Trezor and Ledger see incremental demand from Coldcard defectors, and whether Coinkite's migration guidance is followed closely enough to prevent a follow-on drain from leftover vulnerable seeds still sitting on patched devices.

Related tokens
$BTC

Frequently asked questions

  1. What happened in the Coldcard exploit?

    A firmware flaw dating to March 2021 weakened seed-generation randomness on certain Coldcard models. An attacker reconstructed private keys offline and drained roughly $70M in BTC from 1,196 addresses over about 41 minutes on July 30.

  2. How much bitcoin was stolen in the Coldcard hack?

    Initial on-chain reports flagged about 594 BTC ($38M). Galaxy Research later expanded the figure to 1,082.65 BTC, roughly $70M at the time, taken from 1,196 addresses.

  3. What is Coinkite telling Coldcard users to do?

    Coinkite has released emergency firmware updates and is asking users who generated seeds on affected versions to create entirely new seeds on patched devices and migrate funds carefully. Updating firmware alone does not secure an already-created vulnerable seed.

  4. What did CZ say about the Coldcard exploit?

    Binance founder Changpeng Zhao posted on X that even hardware wallets can have bugs and suggested splitting funds across multiple wallets as a mitigation, while noting that diversification introduces its own key-management risks.

  5. Does the Coldcard exploit mean hardware wallets are unsafe?

    The case shows that long-established hardware wallets can harbor undetected seed-generation flaws for years. It does not invalidate hardware-wallet security broadly, but it pushes serious holders toward multi-wallet and multi-vendor strategies.

Source attribution
Aggregated from CoinDesk · Verified · Last refreshed 1h ago
Open original →