- A firmware flaw in a March 2021 Coldcard release has enabled attackers to systematically drain bitcoin from thousands of wallets by reproducing keys generated with weak software-based randomness.
- On July 30, an opening wave drained 1,083 bitcoin from 1,196 addresses in just 41 minutes, worth about $70 million at the time.
- By July 31, Coinkite had shipped emergency firmware for every affected model and release track to address the vulnerability.
- The third wave of attacks drained roughly 208 bitcoin from 1,912 addresses, bringing total observed losses to 1,367 bitcoin, nearly $89 million, from 4,585 addresses.
- The flaw traces to a March 2021 firmware build that routed seed generation to a predictable software randomiser instead of the chip's hardware RNG, leaving a bounded set of possible keys that can be reproduced offline.
- Galaxy Research has flagged that the third wave of sweeps is targeting smaller balances and changing how funds are collected on-chain.
A firmware vulnerability in Coldcard Bitcoin wallets has resulted in significant financial losses, with nearly $89 million drained from 4,585 addresses through three waves of attacks. The flaw, originating from a March 2021 firmware release, allowed attackers to exploit weak keys generated by the device.4
The first wave of attacks on July 30 saw 1,196 addresses compromised in just 41 minutes, resulting in the theft of 1,082.65 BTC worth approximately $70.2 million at the time. Subsequent waves have targeted smaller balances, with the latest draining 208 BTC from 1,912 addresses between Friday and Saturday, averaging just over 0.1 BTC per victim.2
The vulnerability stems from a deterministic software pseudorandom number generator (PRNG) used in seed generation, which allowed attackers to reproduce keys offline. Coinkite, the manufacturer, has released emergency firmware updates, but existing seeds remain vulnerable. Galaxy Research has indicated that the sweeping attacks are likely the work of a single operator, although it remains unclear if all three waves are coordinated.
Coinkite advises users to replace their seeds and emphasizes that a strong, unique BIP-39 passphrase can mitigate risks. However, the ongoing thefts highlight the critical need for enhanced security measures in cryptocurrency wallets.
The disclosure follows earlier research by Coinspect, which identified a separate weak-PRNG flaw in older software wallets that resulted in over $5 million in losses across multiple cryptocurrencies since May.
“Galaxy Research counts 1,083 bitcoin drained from 1,196 addresses in the July 30 opening wave; the latest sweep sends each victim's coins to separate pay-to-witness-script-hash outputs, complicating onchain tracking. The firm says the chain cannot reveal whether one operator is behind all three sweeps.”