Coldcard wallet exploit nets over 1,800 BTC from self-custody users; flaw traced to 2021-era firmware RNG weakness
AI Market Summary
Galaxy Research reports a Coldcard hardware wallet firmware flaw (weak RNG) active since 2021, linked to theft of over 1,800 BTC from self-custody users and impacting 7K+ addresses. The incident elevates operational and counterparty risk perceptions around self-custody tooling, potentially tightening risk appetite and increasing demand for audits, updates, and more conservative wallet practices in the near term.
Impact level
● Medium
Affected assets
BTC/USDT-0.08%
AI Insight · BTC/USDTAI Insight
▼ Bearish
Trade now
⚠️ AI-generated insights are based on news content and are provided for informational purposes only. They do not constitute investment advice or represent the views of BingX. Investing involves risk. Please trade responsibly.
More than 1,800 BTC was stolen from self-custody users in a recent attack targeting Coldcard hardware wallets. Galaxy Research said the issue stems from a weak random number generator embedded in the device's firmware, a vulnerability that has been present since 2021. The firm estimates more than 7,000 addresses were affected.