A flaw in COLDCARD hardware wallet firmware made some recovery seeds predictable, and attackers used the weakness to steal about 594.48 BTC—roughly $38 million—from around 500 wallets in a coordinated sweep lasting about 25 minutes. Reporting tied the theft to wallets created on affected devices, with the losses spread across roughly 500 transactions in three blocks and most of the stolen funds—about 562 BTC—later consolidated into a single address. The targeted wallets were reportedly single-signature wallets holding more than 0.15 BTC each, and many had been dormant for years.
The weakness was traced to firmware logic that failed to properly use the device hardware random number generator and instead relied on a predictable fallback with a 32-bit reseed mechanism, reducing entropy in generated seeds. Coinkite said the issue affects Mk3 devices running firmware 4.0.1 and later, and also affects Mk4, Mk5, and Q devices that generated seeds before fixed firmware was released; the company urged users to update firmware, create entirely new seeds, and move funds because updating alone does not repair already weak seeds. Coinkite added that wallets protected with sufficient independent dice-roll entropy or a strong BIP-39 passphrase are better protected, while TAPSIGNER, SATSCARD, and OPENDIME are not affected.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
18 events from the most recent confirmed update back to the earliest known activity.
TRM Labs reported limited laundering activity from the Coldcard thefts, including a 64.9 BTC deposit to Wasabi and 200 ETH sent to Tornado Cash. The observed onward movement remained relatively limited, with most funds still concentrated in a small number of attacker-controlled addresses.
On Monday, attackers launched a fourth wave of sweeps against vulnerable Coldcard wallets, stealing 448.7 BTC from 709 potential victim addresses. The new wave raised cumulative estimated losses to about 1,816 BTC, worth roughly $114 million, across more than 5,200 addresses, and researchers said the attacker used replace-by-fee transactions that briefly allowed some victims to outbid the thefts in the mempool.
Coinkite said its legal team will work with law enforcement across multiple jurisdictions to help identify the attackers behind the Coldcard wallet thefts. The FBI declined to comment publicly on whether it is investigating the campaign.
By August 1, 2026, reported losses tied to the Coldcard seed-generation flaw had climbed to 1,367.05 BTC, valued at about $88.6 million, stolen from 4,585 addresses. The reporting also noted the third theft wave differed from the first two, suggesting revised tooling or possibly a separate attacker exploiting the same vulnerability.
On July 31, Coinkite released emergency firmware across every affected COLDCARD model and release track to address the seed-generation flaw. The company warned that installing the update does not repair already-generated weak seeds and told users to create new seeds on patched firmware and move funds.
Galaxy Research said blockchain analysis found attackers drained more than 1,000 BTC from 1,196 wallets in 41 minutes on July 30, and later identified two additional suspected waves of suspicious activity. Those added waves raised estimated losses from the Coldcard-related thefts to nearly $89 million.
Coinkite said every COLDCARD Mk3 running firmware 4.0.1 and later contains the entropy flaw for device-generated seeds, and identified 4.0.1 as first released in March 2021.
The flawed commit was included in COLDCARD firmware version 4.0.0, released in March 2021, introducing the seed-generation weakness into shipped firmware.
Block traced the vulnerability to a commit dated March 1, 2021 that led COLDCARD firmware to bypass the hardware RNG and fall back to weaker software-derived entropy during seed generation.
Galaxy Research said it provided details on nearly 600 suspected attacker-controlled addresses to federal investigators, compliance organizations, and cybersecurity teams. The disclosure reflects a new investigative response tied to the Coldcard-linked theft activity.
Public reporting described the flaw as a predictable RNG fallback and 32-bit reseed issue caused by a disabled hardware-RNG path, constraining entropy in affected COLDCARD firmware and exposing generated secrets.
Following the Coldcard seed-generation crisis, Coinkite halted shipments of devices carrying affected firmware and destroyed remaining inventory with the vulnerable versions. The company also urged users who had generated a seed on a Coldcard to move funds immediately.
Coinkite later broadened its warning to say the issue also affects Mk4, Mk5, and Q devices that generated seeds before fixed firmware releases. It specified regeneration after updating for seeds created on Mk4 or Mk5 before 5.6.0 and on Q before 1.5.0Q.
Coinkite published an emergency security advisory warning that seeds generated on affected COLDCARD firmware may be predictable enough for offline key recovery. The company urged users to update firmware, generate entirely new seeds, and migrate funds immediately because updating alone cannot fix already weak seeds.
Block's engineering and security teams analyzed the flaw and reported their findings to Coinkite, which confirmed receipt. Both parties described the analysis as preliminary.
After the Coldcard thefts began, multiple small deposits carrying OP_RETURN text messages were sent to a Bitcoin address identified by analysts as controlled by the attacker. The messages included alleged victim pleas for refunds, unrelated requests, and even an offer to help launder the stolen funds.
After the draining transactions, the attacker consolidated more than 562 BTC into a single destination wallet. At the time of reporting, those consolidated funds had not yet moved further.
An unknown attacker stole approximately 594 BTC, worth about $38 million, from around 500 wallets in a coordinated operation. The theft unfolded across about 25 minutes and three Bitcoin blocks, with funds taken from 1,324 transaction outputs.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
19 references tracked. Mallory keeps watching after this page renders.
trmlabs.com
Open sourcexakep.ru
Open sourcexakep.ru
Open sourcetherecord.media
Open sourcethecybersecguru.com
Open sourceblog.coinkite.com
Open sourceblog.coinkite.com
Open sourceengineering.block.xyz
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.