Hackers stole more than $35 million in Bitcoin from wallets last Thursday, and the confirmed total has climbed past $111 million, according to data from Galaxy Research. The theft, which could exceed $130 million, traces to a firmware bug in Coldcard Mk3 hardware wallets that Coinkite says went unnoticed for years.
The bug behind the heist
Coinkite, the maker of Coldcard devices, said the problem started with firmware version 4.0.1 in March 2021. Seed generation fell back to a weak software-based random number generator instead of the hardware's true random number generator. The company said the flaw "silently went unnoticed" and that its potential impact grew with every release. Coinkite urged users to update their software or move funds.
Victims and losses
Galaxy Research's Alex Thorn reviewed 250 victim reports. The median loss was 1.022 BTC, the average 4.04 BTC, and one wallet lost 58.97 BTC. Stolen coins had typically sat untouched for about 3.5 years, with 88% of the pilfered funds at least a year old. By address, losses ranged from a median of 0.014 BTC to a mean of 0.212 BTC.
Users move to exchanges
That long dormancy appears to have pushed cautious holders into action. Some are moving coins to other storage solutions, including exchanges, according to the research.
Coinkite's guidance is clear: update the firmware or move the bitcoin. With the confirmed total already past $111 million and more victims likely to come forward, the final number will depend on how quickly the remaining affected wallets get secured.




