A firmware flaw in older versions of the Coldcard Bitcoin hardware wallet has been linked to a series of large cryptocurrency thefts that may have resulted in losses of up to 1,367.05 BTC, worth around $88.6 million, according to new findings from Galaxy Research.
The investigation began after an attacker drained 1,196 Bitcoin addresses in just 41 minutes on July 30, stealing 1,082.65 BTC, valued at approximately $70.2 million at the time. Galaxy Research analyzed the blockchain activity and connected the incident to a long-standing firmware issue in Coldcard devices manufactured by Coinkite.
The vulnerability dates back to March 2021, when a firmware integration mistake caused wallet seed generation to rely on a predictable software-based pseudorandom number generator (PRNG) instead of the device’s hardware random number generator. This significantly reduced the randomness used to create recovery seeds, making them more vulnerable to being reproduced under certain conditions.
Researchers explained that if an attacker can estimate details such as a device’s unique identifier, timer state, and previous random number usage, they may be able to recreate possible wallet seeds offline. Those candidate seeds can then be checked against public blockchain data to identify wallets holding cryptocurrency.
Coinkite released emergency firmware updates for all affected Coldcard models on July 31, but warned that simply updating the device does not fix wallets created with vulnerable firmware. Users whose seeds were generated on affected versions are advised to create a brand-new seed using the patched firmware and immediately transfer their funds. Restoring an old recovery seed on an updated device or another wallet does not remove the weakness.
The issue was traced to Coldcard’s production configuration, where a firmware setting unintentionally caused the software to use MicroPython’s Yasmarang fallback random number generator instead of the intended hardware source. That fallback generator was initialized using predictable values from the device, including its unique chip ID and timer registers, without collecting fresh entropy afterward.
According to Coinkite, the flaw reduced effective entropy to roughly 40 bits on the Mk3 and around 72 bits on Mk4, Mk5, and Q models, far below the 128-bit security expected from a standard 12-word BIP-39 recovery seed. Researchers noted that the practical difficulty of exploiting the flaw depends on several factors, including knowledge of the device’s unique ID, boot timing, previous random number calls, and the cost of deriving candidate wallets.
The exposure depends on the firmware version that was running when the recovery seed was created. Galaxy Research and Coinkite identified vulnerable firmware across several Coldcard models, including older Mk2, Mk3, Mk4, Mk5, Q, and Edge release tracks before their respective patched versions.
Coinkite said wallets created using at least 50 private, fair, and independent dice rolls for entropy are not affected by this bug alone. However, users who are uncertain about how their seeds were generated are encouraged to migrate to newly created wallets. The company also noted that while a strong BIP-39 passphrase adds another layer of protection, it still recommends replacing affected seeds. Multisignature wallets remain safer only if they are not built entirely from vulnerable Coldcard devices. Other Coinkite products, including TAPSIGNER, OPENDIME, and SATSCARD, use different codebases and are not impacted.
Galaxy Research emphasized that it has not identified the attacker behind the thefts. The firm noted that the blockchain transaction pattern it observed could also resemble legitimate wallet consolidation, meaning the on-chain activity alone cannot definitively prove theft.
In a later update, Galaxy Research identified two additional suspected waves of similar wallet sweeps, increasing the observed total to 4,585 affected addresses and approximately 1,367.05 BTC, valued at around $88.6 million. While the first two waves may have been carried out by the same operator, researchers cautioned against assuming the third wave involved the same attacker. They also stressed that their conclusions are based on blockchain analysis and have not yet been computationally verified to show that every affected wallet originated from weak Coldcard-generated entropy.
If this article helped you, please consider supporting our work. Every small contribution keeps Abijita.com independent and running.
Galaxy said the activity is still ongoing and has shared information on roughly 600 suspected attacker-controlled Bitcoin addresses with federal investigators, compliance organizations, and cybersecurity investigators.





