Coldcard firmware flaw leaves wallet seeds predictable; attackers steal about 1,816 BTC from 5,200+ addresses
AI Market Summary
A firmware bug in Coinkite's Coldcard hardware wallet reportedly made some generated seeds guessable, enabling coordinated theft of ~1,816 BTC from 5,200+ addresses. The incident undermines confidence in self-custody security assumptions because offline storage can become direct key exposure when seed generation fails. Near term, it can accelerate wallet migrations, increase operational risk around key rotation, and raise caution across hardware-wallet users.
Impact level
● Medium
Affected assets
BTC/USDT+0.92%
AI Insight · BTC/USDTAI Insight
▼ Bearish
Trade now
⚠️ AI-generated insights are based on news content and are provided for informational purposes only. They do not constitute investment advice or represent the views of BingX. Investing involves risk. Please trade responsibly.
A firmware defect in Coldcard hardware wallets made device-generated recovery seeds guessable, enabling attackers to replicate private keys and drain funds. Roughly 1,816 BTC was swept from more than 5,200 addresses in four coordinated waves.
Victims described rapid losses. Jonathan Goodman said all of his wallets were emptied within seven minutes on July 29, including 18.25 BTC stored on a Coldcard that had never been connected to the internet. Tim Lamb said 2 BTC was taken before he could restore access, even with a neighbor's help.
Users are now rushing to move coins because the vulnerability allows adversaries to reproduce keys tied to affected seeds. Coinkite has released patched firmware for every model, paused shipments, and destroyed remaining inventory that carried the impacted firmware.
Why it matters: Seed-generation failures can turn offline storage into direct key exposure, potentially undermining confidence in self-custody tools.
Market sentiment: Bearish, stress-on, tech-driven de-risking. The predictable-seed issue may push investors to reduce reliance on affected self-custody setups.
Similar past cases: In June 2023, Atomic Wallet users lost more than $35 million through unauthorized withdrawals; Atomic said fewer than 1% of monthly active users were affected. That episode led to urgent transfers and tracking efforts while the cause remained unclear (Fortune). The key difference: Atomic Wallet was a hot-wallet incident, while the Coldcard case centers on a hardware-wallet seed-generation flaw.
Ripple effects: A seed-generation defect can extend beyond individual losses into broader self-custody distrust as users rush key rotations and migrate wallets. If exposed seeds remain funded, attackers may continue draining wallets before recovery steps are completed. If users can't confirm whether a seed is affected, more conservative custody behavior could spread across hardware-wallet users.
Opportunities and risks: Verifying the fixed firmware and moving funds to newly generated, unaffected keys can serve as a risk-reduction signal via key rotation. The primary risk remains leaving funds on affected seeds, which increases exposure to further coordinated sweeps.