Coldcard bitcoin wallet exploit grows to $89 million

Galaxy Research identified a second and third wave of thefts tied to the same Coldcard hardware wallet flaw first reported on 30 July, when roughly 594 bitcoin was drained from about 500 dormant addresses in under 30 minutes. The running total has since grown to 1,367 bitcoin, worth roughly $89 million, taken from 4,585 addresses.

The vulnerability traces to a March 2021 firmware build affecting Coldcard Mk3 devices running versions 4.0.1 through 4.1.9. Rather than routing entropy through the device's hardware random-number generator, the flawed firmware generated wallet seeds through a software RNG, making the resulting private keys feasible to reconstruct offline without physical access to the device. Coinkite, the wallet's maker, issued a security advisory and shipped patched firmware on 1 August.

The scale of the response, with holders moving unaffected bitcoin back onto exchanges as a precaution, has itself become a bigger short-term driver of on-chain activity than the theft.