A critical firmware build error affecting Coldcard hardware wallets has been linked to one of the largest hardware wallet security failures in recent years, after attackers reportedly drained roughly $38 million worth of bitcoin from more than 500 wallets in about 25 minutes. The incident has raised fresh concerns about the security of wallet seed generation and the risks of software flaws in devices designed to protect digital assets.
The vulnerability stems from a firmware bug that significantly reduced the randomness used when generating wallet recovery seeds. Instead of producing cryptographically strong entropy, affected devices generated seeds that attackers could predict and brute force, allowing them to reconstruct private keys and transfer funds without interacting with the wallet owners.
How the vulnerability worked
According to information released following the incident, the flaw originated in firmware introduced in 2021. The bug caused certain Coldcard models to generate wallet seeds with dramatically less entropy than intended.
Investigators said the issue primarily affected:
- Mk3 devices running firmware version 4.0.1 or later.
- Mk4, Mk5, and Q models that generated seeds before newly released firmware updates, although these newer devices retained additional entropy that made attacks significantly more difficult.
The attacker reportedly generated candidate seed phrases, derived wallet addresses, and matched them against public blockchain data before rapidly emptying vulnerable wallets. Approximately 594 BTC, valued at about $38 million, was stolen during the coordinated attack.
Emergency response
The wallet manufacturer has released patched firmware for supported models and urged users to install the latest updates immediately. However, updating the firmware does not repair wallets whose recovery seeds were already generated using the flawed software.
Users who created seeds on affected firmware have been advised to migrate funds to entirely new wallets created after installing the patched firmware. Those who generated their own entropy using physical dice or relied on strong passphrases may face substantially lower risk, depending on their setup.
The incident highlights that hardware wallets remain dependent on secure firmware and correct implementation of cryptographic processes. While hardware isolation protects private keys from many online attacks, a flaw in key generation can undermine those protections before a wallet is ever used. The breach is likely to prompt broader scrutiny of firmware verification, entropy generation, and independent security audits across the hardware wallet industry.