Skip to content
event

COLDCARD Firmware Flaw Drains $115M Across Four Bitcoin Attack Waves

A weak entropy bug in COLDCARD's random number generator let attackers drain at least 1,367 BTC from 4,585 addresses across four coordinated attack waves starting July 31. The exploit dismantled the air-gapped security model that made COLDCARD one of Bitcoin's most trusted self-custody devices.

COLDCARD Firmware Flaw Drains $115M Across Four Bitcoin Attack Waves
Methodology
Learn more

Original analysis, verified sources, real-world experience

What happened

By the fourth wave of coordinated attacks, more than 800 COLDCARD wallets had been emptied, each drained through a single firmware-level flaw in how the device generates private keys. According to BeInCrypto ES, the first three confirmed waves accounted for 1,367.05 BTC swept from 4,585 addresses. A fourth wave added 462 new victims and another 486 BTC, per DiarioBitcoin, with total reported losses reaching $115M.

The attack surface extends further than the initial figures suggest. CoinDesk reported a 12-year-old Bitcoin wallet moving $31 million on August 4 as part of a broader migration wave triggered by the breach, with multiple wallets dormant since 2013 suddenly becoming active. This suggests the entropy flaw affected a far wider generation of devices than the initial wave counts implied.

Adding a troubling dimension, DiarioBitcoin reported that Anthropic's Claude AI model identified the root vulnerability in just eight minutes after being given access to the firmware code. The speed of that discovery underlines how long the flaw sat undetected in shipping hardware.

How the attack worked

The vulnerability class is Non-Random Private Key Generation: a weak entropy source inside COLDCARD's random number generator (RNG). Bitcoin private keys must draw from a cryptographically secure entropy pool of at least 256 bits. When an RNG produces values with insufficient randomness, the keys it generates occupy a fraction of the possible keyspace rather than being uniformly distributed across it.

Attackers scan this reduced keyspace programmatically, generating the same keys the device would have produced, then sweep any addresses holding funds. The approach requires significant compute but is entirely feasible once the target pool is narrow enough. Because the flaw exists at the key generation stage, the air-gapped nature of the device offers no protection. Air-gapping prevents network intrusion; it cannot protect a key that was mathematically weak from the moment it was created.

Decrypt noted that air-gapped wallets reduce exposure to hackers but are not immune from threats rooted in the device itself. Jameson Lopp, cited by DiarioBitcoin, argued the exploit exposes the practical ceiling of the "don't trust, verify" mantra: most users cannot audit firmware-level entropy generation, so they placed trust precisely where a flaw lived.

What user funds are at risk

Any funds held in wallets generated by affected COLDCARD firmware versions are at risk. The confirmed total across three waves stands at 1,367.05 BTC from 4,585 addresses, with a fourth wave adding 462 more addresses and 486 BTC, per DiarioBitcoin. Recovery odds for already-drained wallets are effectively zero. Bitcoin transactions are irreversible by design, and ZachXBT declined to trace the stolen funds, citing lack of community support, removing one of the few mechanisms that sometimes produces actionable intelligence after a major theft.

On-chain data cited by ForkLog shows that holders are migrating remaining funds to new wallets rather than exchanges, a rational move that limits further exposure without triggering slippage. Glassnode data confirmed eight on-chain metrics printed values well above their two-year median on the day the news broke, reflecting the scale of coordinated migration activity.

Collateral damage is already spreading beyond COLDCARD users. BeInCrypto documented panic affecting Ledger's reputation by association, with users questioning hardware wallet security sector-wide. The breach has opened a broader trust crisis in self-custody that no single firmware patch will quickly close.

Pattern recognition

This exploit class has clear historical precedent. In 2013, a critical Android RNG flaw produced weak entropy for Bitcoin wallet apps, letting attackers reconstruct private keys from ECDSA signatures. The attack surface and methodology mirror COLDCARD exactly: a firmware-level RNG producing keys that appear valid but occupy a predictable subset of keyspace. Developers issued emergency patches, but not before significant funds were swept from addresses generated on vulnerable Android versions.

The 2022 Profanity vanity address generator hack is a closer structural parallel. Profanity used a 32-bit seed to generate Ethereum addresses, and researchers demonstrated the entire keyspace could be brute-forced on commodity GPU hardware in hours. Wintermute alone lost $160 million from addresses created with the tool. The lesson from Profanity went unlearned broadly enough that COLDCARD repeated the structural error on a different chain and in a different form factor, nearly four years later.

The 2018 IOTA seed theft completes the pattern. A third-party online seed generator produced seeds with weak entropy, and attackers who ran the same generator recovered victims' seeds and emptied wallets without ever touching the IOTA network directly. In each of these three cases, the common thread is a generator that presents a correct-looking interface to the user but fails at the statistical level where security actually lives.

What to do now

Move funds immediately from any COLDCARD-generated address to a new address generated by a different, unaffected device. Use an open-source software wallet on an air-gapped machine with a documented entropy source, or a hardware wallet from a different manufacturer with a clean audit record. Do not generate a new COLDCARD address until Coinkite publishes a verified firmware patch and an independent audit confirms the RNG fix. Updating firmware does not protect keys already generated under the vulnerable version.

The multi-wave pattern confirmed by BeInCrypto ES and DiarioBitcoin shows attackers scanning the vulnerable keyspace continuously, not in a single pass, meaning the threat remains active now. If you have not been drained yet, act before the next wave reaches your address.

When migrating, send funds to a new self-custody address rather than an exchange, matching the approach ForkLog confirmed experienced holders are taking. Generate a fresh seed on a device with a publicly audited entropy source, back up the seed phrase on paper in at least two physically separate locations, and consolidate your balance in a single transaction to avoid leaving dust behind.

Going forward, treat entropy auditability as a minimum requirement when evaluating any hardware wallet. Any device whose RNG implementation is closed-source or lacks published independent entropy testing should not hold significant funds. The "don't trust, verify" standard must apply to key generation itself, not just to transaction signing.

FAQ

Are COLDCARD wallets that have not been drained yet still at risk?

Yes. Attacks have rolled out across four confirmed waves over multiple days, and keyspace scanning appears to be ongoing. Any wallet generated by the affected firmware versions remains at risk until funds move to an address created by a different, unaffected device.

Can funds stolen in the COLDCARD hack be recovered?

No. Bitcoin transactions are irreversible, and ZachXBT declined to trace the hack due to lack of community support, removing one of the few realistic paths to identifying attacker addresses.

Does this exploit affect other hardware wallets such as Ledger?

No confirmed evidence shows Ledger devices share the same RNG flaw. As BeInCrypto reported, the panic around COLDCARD has damaged Ledger's reputation by association, but the technical vulnerability is specific to COLDCARD firmware at this stage.

This article is for educational purposes and is not investment advice. Cryptocurrencies carry high risk. Only trade with funds you can afford to lose.

CoinMagnetic

CoinMagnetic Team

Crypto investors since 2017. We trade with our own money and test every exchange ourselves.

Updated: August 2026

Follow our analysis on Telegram

We publish analysis, digests and forecasts on our Telegram channel.

Follow the channel