Loading market data...

Coldcard Firmware Bug Led to $70M Bitcoin Theft, Users Told to Move Funds

Coldcard Firmware Bug Led to $70M Bitcoin Theft, Users Told to Move Funds

A firmware bug in Coldcard hardware wallets dating back to March 2021 has resulted in the theft of over $70 million in Bitcoin, with attackers exploiting weak entropy to drain funds from nearly 1,200 addresses. Coinkite, the company behind Coldcard, confirmed the issue this week and urged users to move their funds immediately.

The vulnerability

The bug was introduced in firmware version 4.0.1, released in March 2021. It caused seed generation to produce only about 40 bits of entropy instead of the standard 128 bits, making private keys vulnerable to brute-force attacks. The issue affected all Coldcard models — Mk3, Mk4, Mk5, and Q — though Coinkite initially said only the Mk3 was impacted. Attackers exploited the weakness to drain funds from 1,196 Bitcoin addresses, stealing over 1,082.65 BTC, worth more than $70 million according to Galaxy Research and Block engineers. On Thursday, 594.5 BTC (roughly $35.7 million) was moved from single-signature addresses, indicating the attackers are still active.

Coinkite's evolving response

Coinkite admitted the problem and advised users to move their funds. The company first said only the Mk3 needed precautions, but later expanded that warning to include Mk4, Mk5, and Q models. Kevin Loaec, CEO of Wizardsardine, warned that every mnemonic generated via Coldcard since 2021 is now effectively public. Bitcoin engineers have echoed that warning, urging anyone who used a Coldcard to transfer their coins to new wallets created on secure devices.

What users should do

There is no software patch that can fix already-compromised seeds. The only safe course is to generate a new seed on a trusted device — ideally a hardware wallet not affected by this bug — and move all funds immediately. The movement of 594.5 BTC on Thursday suggests the attackers are still siphoning coins, and the full scope of the theft may not be known for some time.