In a striking incident, an attacker exploited a critical vulnerability in Coldcard hardware wallets, successfully draining 594.48 bitcoin, valued at approximately $38.3 million, within a span of 25 minutes. The attack targeted approximately 500 individual single-signature wallets, wiping out their contents swiftly. Over the course of a few minutes, 1,324 segments of bitcoin were moved through 500 transactions during a three-block window. This event underscores the weakness in the key generation process of these hardware wallets, which is a critical line of defense in securing digital assets.
The vulnerability originated in Coldcard firmware 4.0.0, released in March 2021. This update led the hardware to bypass its hardware randomness generator, which is essential for creating truly random keys, and instead fell back to a predictable software method. The software used nonsecret data, such as the device's serial number and clock values, to generate keys, making it easier for an attacker to guess the private keys. The predictable nature of these keys is what made the attack possible, as it undermined the security intended by the hardware design.
Exploitation of the Flaw
The flaw was identified by Block's Bitcoin engineering and security teams, who traced the issue back to a specific firmware commit dated March 1, 2021. This commit was part of firmware 4.0.0 and caused the device to bypass hardware randomness. Instead, it relied on a software-based alternative that used guessable data. This shift compromised the integrity of private keys, which should have been nearly impossible to guess, leaving the wallets vulnerable to theft.
Coinkite, the Canadian firm behind Coldcard, issued a warning to users who created seeds on Mk3 devices using firmware 4.0.1 or later. The company reassured users that Mk4, Q, and Mk5 devices do not appear to be affected by the flaw. Collaborating with researchers, Coinkite aims to determine the full extent of the issue. This proactive approach is aimed at protecting users and preventing further losses.
The attack specifically targeted wallets with predictable software-generated keys. Notably, many of the affected wallets had remained dormant for years, and the funds dated back to 2021 through 2026, aligning with the timeframe of the flaw's introduction. Each impacted wallet contained more than 0.15 BTC, indicating substantial individual losses, especially for those holding larger amounts over long periods.
Coldcard hardware wallets are designed to generate truly random seed phrases that are extremely hard to guess, ensuring the security of users' funds. However, the flaw in the key generation process rendered these seeds guessable. The impact was not limited to wallet seeds; it also exposed other sensitive data, including paper wallet private keys, seed-splitting masks, device cloning keys, and Key Teleport transfers. This broader vulnerability highlights the importance of secure key generation in maintaining the integrity of digital assets.
Market Impact
Despite the theft of such a large amount, the cryptocurrency market did not experience significant price volatility. Bitcoin remained above $64,000 during early Asian trading hours, and the substantial drain of funds did not appear to impact the market price. Block chose to release its findings before completing full testing, as the theft was already in progress. Both Block and Coinkite described their analysis as preliminary but ongoing, emphasizing the need for further investigation and collaboration to address the security issue effectively.
Coldcard's $38 million (so far) exploit shakes faith in self-custody, may push investors to ETFs. A software bug in popular hardware wallet Coldcard that led to the theft to this point of nearly 600 bitcoin worth roughly $38 million is prompting questions about security and whether managing private keys has become too risky for everyday investors.
Security experts say the hack highlights growing operational risks around self-custody as cyber threats evolve. The incident may accelerate adoption of regulated custodians and spot Bitcoin ETFs, some industry observers said.
Long among Bitcoin's biggest selling points has been that investors don't need to trust banks and exchanges to safeguard their money. That promise suffered one of its biggest blows — maybe ever — after a flaw in popular hardware wallet maker Coinkite's Coldcard allowed attackers to recreate wallet recovery phrases and steal bitcoin from what users believed were securely self-custodied wallets. The flaw has since been patched, but the fallout continues. Affected users must generate entirely new wallets and move their funds because updating the firmware alone doesn't eliminate the risk.
'Move your funds now' 'If you generated a seed using a Coldcard wallet, move your funds now, using our updated best practices, before reading further,' wrote Coinkite CEO NVK in an open letter a short time ago. He added that while the fix protects new seeds going forward, it does not fix seeds already generated on vulnerable firmware.
The exploit exposes a growing tension as bitcoin enters the financial mainstream: self-custody remains one of the cryptocurrency's defining features, but the technical burden of securing private keys may increasingly push ordinary investors toward professional custodians, exchanges, and regulated investment products instead.
Some prominent bitcoin advocates say the incident is among the most damaging failures of self-custody the industry has experienced. 'This is the worst hit in bitcoin history to the most knowledgeable and 'properly secured' bitcoiners,' said Bitcoin commentator Guy Swann. 'This isn't an exchange getting hacked because of hot keys. This is thousands of individuals having their personal private keys recreated out from underneath them.'
For years, bitcoin advocates have argued that holding private keys removes the counterparty risk of centralized exchanges, a lesson reinforced by failures such as FTX. Analysts now argue that users have simply exchanged one set of risks for another.
'The self-custodial hardware space is a disaster at this point and creates more bad rep for the industry than anything else,' said Lorenzo Valente, director of digital asset research at ARK Invest. 'In practice, consumers have traded counterparty risk for software risk, hardware risk, supply-chain risk, phishing risk, backup risk, and the possibility of losing everything through one mistake,' he said. 'Frankly, you are better off today holding funds across several publicly-traded exchanges or ETFs.'
The Coldcard flaw illustrates that challenge. Researchers found that certain firmware versions generated wallet seeds using far less randomness than intended, making them susceptible to brute-force attacks. Even the recommended fix drew criticism. 'You just can't ask people to roll dice to be secure with your self custody,' Casa CEO Nick Neuman said, referring to guidance that users supplement wallet-generated randomness with physical dice rolls. 'It's a non-starter for 99% of people.'
Security is not passive anymore The incident also highlights how rapidly cybersecurity threats are evolving as artificial intelligence lowers the cost of discovering software vulnerabilities. 'The idea of your bitcoin resting easy in some secret location while you enjoy life not worrying about it is currently unrealistic,' well-followed Taproot developer Udi Wertheimer wrote on X. Instead of treating security as something users can set up once and forget, he argued, bitcoin holders increasingly need either to constantly monitor new threats themselves or rely on professional custodians with dedicated security teams. 'If you don't want to worry yourself you need to pay someone else to be worried,' he said.
The Coldcard exploit also fits a broader trend in crypto attacks. According to blockchain security firm Blockaid, most losses in the first half of 2026 came not from smart contract hacks but from compromised keys and operational security failures. 'Coldcard fits that pattern, with the exposure originating at the key generation stage,' said Ido Ben-Natan, Blockaid's co-founder and CEO. He said the incident highlights how much users rely on security systems they never directly interact with. 'A hardware wallet's security ultimately comes down to the firmware and systems users interact with but nev

