Suspicious transfers linked to a software flaw in Coldcard hardware wallets have reached 1,367 Bitcoin. According to an on-chain analysis by Galaxy Research, funds were moved from 4,585 Bitcoin addresses during three separate waves. The assets were worth approximately $88.6 million at the time of the transfers.
The incident was not caused by a vulnerability in the Bitcoin network or its underlying protocol. Instead, it has been linked to certain Coldcard firmware versions that generated wallet seed phrases with far less randomness than intended.
1,083 Bitcoin Moved in 41 Minutes
The largest transfer wave occurred on July 30, when approximately 1,083 Bitcoin was moved from 1,196 addresses in just 41 minutes.
Two further waves brought the total to 1,367 Bitcoin across 4,585 addresses. The final wave targeted wallets with smaller balances and used different transaction methods, raising the possibility that the attacker had changed tactics.
Galaxy Research has not confirmed whether all three waves were carried out by the same person or group.
The findings are based on transaction patterns recorded on the Bitcoin blockchain. It has not been technically confirmed that every address involved was created using vulnerable Coldcard firmware.
The estimated $89 million therefore represents the value of suspicious transfers identified so far, rather than a fully verified total of confirmed losses.
The Flaw First Appeared in 2021
The weakness first appeared in a firmware release issued in March 2021 and later affected additional Coldcard models.
The vulnerable software generated wallet seed phrases from a much smaller range of possible values than expected. This made the resulting private keys easier to predict than those produced by a properly functioning system.
An attacker with sufficient computing power could test possible keys offline and search for matches with funded Bitcoin addresses. Physical access to the device or a direct internet connection to the wallet was not required.
Coldcard manufacturer Coinkite said wallets created on Mk2 and Mk3 devices running firmware versions 4.0.1 through 4.1.9 may be at risk. Some seed phrases generated on Mk4, Mk5 and Q devices before corrected firmware was installed may also be affected.
Updating the Device Is Not Enough
Coinkite has released updated firmware for the affected devices. Installing the latest version, however, does not make seed phrases created with vulnerable firmware secure.
Users who generated a wallet with an affected version are advised to update their device, create an entirely new seed phrase and transfer their Bitcoin to the new wallet. A small test transaction should be completed before moving the full balance.
For Coldcard users, the key question is not only which firmware is installed today, but which version was used when the existing seed phrase was first created. Importing an old seed phrase into an updated device does not remove the original security risk.
The incident also underlines a broader point about self-custody: keeping Bitcoin in an offline hardware wallet reduces some risks, but it does not protect users from flaws in the software used to generate their private keys.
Disclaimer: This article is for informational purposes only and does not constitute investment advice or financial guidance.