Coldcard hardware wallet users lost more than $100 million worth of Bitcoin this week after an attacker exploited weak seed phrases generated by vulnerable firmware, according to a report from Galaxy Research. The exploit didn't break the Bitcoin network — it targeted a specific flaw in Coldcard devices running firmware released after March 2021, where seeds carried only about 72 bits of entropy instead of the required 128 bits. That made them guessable with enough computing power.
How the exploit worked
Coinkite, the company behind Coldcard, acknowledged the issue and said affected seeds were generated with insufficient randomness. The company has since patched newer firmware, but it cannot retroactively fix seeds already created on vulnerable devices. Users of Mk3, Mk4, Mk5, and Q models are advised to move their funds immediately. The first confirmed theft occurred on July 31, when 594.5 BTC was swept from about 500 addresses across four blocks.
What Galaxy Research found
Galaxy Research identified 1,596 BTC stolen across roughly 7,300 addresses in three confirmed attack waves. If unconfirmed activity is included, suspected losses could reach 2,055 BTC — worth over $130 million at current prices. About 90% of the stolen Bitcoin hasn't moved; all coins from the first three waves remain in attacker-controlled wallets. The firm shared all confirmed attacker addresses with US law enforcement, crypto exchanges, and blockchain investigation firms.
Can the stolen Bitcoin be laundered?
There's a debate. Galaxy Research's Joe Consorti argued the stolen BTC may be hard to spend because every coin is tracked by law enforcement and analysts on the transparent blockchain. Others counter that the attacker could use mixers, privacy coins, Taproot transactions, and the Lightning Network to launder funds. So far, the attacker hasn't tried — the coins are sitting still.
What Coldcard users should do
Coinkite is urging anyone with a Coldcard Mk3, Mk4, Mk5, or Q to move their funds to a wallet generated on patched firmware or a different device. The Bitcoin price, near $64,000 and up 2% in 24 hours, suggests the market sees this as a hardware flaw, not a protocol failure. But for the roughly 7,300 addresses already drained, the damage is done. Whether the attacker can actually spend that Bitcoin — or whether law enforcement can freeze it — remains the open question.




