A firmware vulnerability in Coldcard hardware wallets led to the theft of approximately $70 million in Bitcoin from roughly 1,200 addresses [1, 2].
This breach undermines the primary security promise of hardware wallets, the isolation of private keys from online threats, by exposing a flaw in how those keys are generated.
Galaxy Research identified the losses through an analysis of the Bitcoin blockchain [1]. The vulnerability resides in the device's random number generator, or RNG, which is responsible for creating the seed phrase used to secure funds [5]. Because the RNG was weakened, attackers were able to derive the private keys of users and drain their wallets [5].
Reports on the total financial impact vary across sources. Galaxy Research and The Hacker News estimate the losses at $70 million [1] and $70.2 million [2], respectively. Other estimates are higher, with BleepingComputer reporting $88.6 million [7], Cointelegraph citing $100 million [10], and Decrypt estimating $114 million [9]. The highest estimate comes from MSN, which placed the loss at $116 million [8].
Similarly, the number of affected addresses is disputed. While The Hacker News reported exactly 1,196 addresses [2] and The Block cited nearly 1,200 [1], MSN reported that 5,200 addresses were impacted [8].
The amount of Bitcoin stolen also varies. The Block noted that more than 1,000 BTC was drained [3], while MSN reported the total at 1,816 BTC [4].
The exploit highlights a critical failure in the firmware's ability to produce truly random seeds. When the randomness of a seed is compromised, the resulting private keys become predictable to sophisticated attackers, effectively turning a "cold" storage solution into an accessible target.
“A firmware vulnerability in Coldcard hardware wallets led to the theft of approximately $70 million in Bitcoin.”
This incident demonstrates that the security of hardware wallets depends entirely on the integrity of their random number generation. If the mathematical foundation of a seed phrase is flawed, the physical air-gap of a device becomes irrelevant. This may lead users to favor wallets with open-source RNG implementations or those that allow users to provide their own external entropy during seed creation.



