A 2021 Coldcard Firmware Flaw Is Still Draining Bitcoin Wallets

By Bartek Hagan

(7 days ago)

3 min read

Share:

Galaxy Research flagged a fourth wave of thefts targeting Coldcard hardware wallets, with roughly 389 Bitcoin swept from 462 addresses in hours. A 2021 firmware flaw that weakened seed randomness left the private keys guessable, and total losses now exceed $88 million.

A 2021 Coldcard Firmware Flaw Is Still Draining Bitcoin Wallets

Key facts

  • Galaxy Research flagged a fourth theft wave that swept about 389 Bitcoin from 462 Coldcard-linked addresses.
  • A 2021 firmware flaw made Coldcard wallet seeds too predictable, leaving private keys guessable.
  • Losses across the waves now exceed 1,360 Bitcoin, worth more than $88 million when moved.

Galaxy flags a fourth wave of Coldcard thefts

Galaxy Research, the analytics team led by head of research Alex Thorn, reported a fourth wave of thefts hitting Bitcoin stored on Coldcard hardware wallets. Over a window of about two and a half hours, roughly 388.93 Bitcoin (BTC) moved through 218 transactions, according to Galaxy Research. The coins left 462 victim addresses and landed in 216 newly created addresses. Galaxy said the affected wallets matched the on-chain shape of Coldcard balances exposed by the flaw. Coldcard is a hardware wallet made by Coinkite that stores Bitcoin keys offline.

On-chain data shows an automated sweep

The withdrawals looked mechanical rather than manual. Galaxy Research measured about 13.8 sweeps per block during the wave, roughly 45 times the rate in a quiet control window before the incident. The attackers built a fresh destination address for each victim instead of pooling the stolen coins. Thorn said the operation looked deliberate and programmatic, and suggested it was probably orchestrated with a large language model (LLM). That approach let the attackers scan and empty many wallets at once.

A 2021 firmware flaw weakened wallet randomness

The thefts trace to a firmware build error introduced on Coinkite's Coldcard devices in March 2021. The bug routed seed generation to a software pseudo-random number generator (PRNG) instead of the device's dedicated hardware random number generator (RNG). It produced wallet seeds with far too little entropy, the randomness that keeps a private key secret, and left many keys guessable. Every single-signature seed generated on the affected firmware since that update carries the same weakness. The affected firmware spanned Coldcard models released across that period, and even later devices held less randomness than the intended 128 bits. Coinkite has released patches and told exposed users to migrate their funds.

Total losses have climbed past $88 million

Losses have mounted through successive waves since the exploit surfaced in late July. Galaxy Research tracked the running total past $75 million, then near $89 million, before this fourth wave added more. An early sweep in late July emptied more than a thousand addresses in about 40 minutes. In all, more than 1,360 Bitcoin has been drained from thousands of addresses, worth roughly $88 million when the coins were moved. Galaxy warned that Coldcard addresses created after the 2021 update stay exposed until holders move the funds.

Bitcoin traded near $62,700 at publication

Bitcoin traded at about $62,725 at the time of publication, down 1.1% over the past 24 hours versus the previous close (CoinPaprika, 3 August 2026). Its market value stood near $1.26 trillion. Bitcoin also sat about 50% below its record high near $126,000 set in October 2025 (CoinPaprika, 3 August 2026). The stolen coins form a small fraction of that total. For the affected holders, though, the losses are severe, since drained single-signature wallets cannot be recovered.

Affected holders are urged to move funds fast

Galaxy Research said holders who still control their keys can respond. It noted that they may be able to broadcast a competing transaction with a higher fee, moving the coins to a safe wallet before an attacker sweeps them. Seeds created with an added passphrase or enough manual dice rolls are not considered exposed. Coinkite has urged all affected users to act without delay. Galaxy framed the response as urgent, because the automated sweeps were still moving funds as it reported.

Cryptocurrencies are highly volatile and involve significant risk. You may lose part or all of your investment.

All information on Coinpaprika is provided for informational purposes only and does not constitute financial or investment advice. Always conduct your own research (DYOR) and consult a qualified financial advisor before making investment decisions.

Coinpaprika is not liable for any losses resulting from the use of this information.

Share:
Go back to All News