Unknown attackers exploited a randomness bug in Coldcard hardware wallets to steal millions of dollars in Bitcoin starting late July [1].
This vulnerability undermines the core security promise of hardware wallets, which are designed to keep private keys offline and impossible to guess. The breach demonstrates that even "cold storage" is susceptible to software flaws that can compromise the generation of seed phrases.
The exploit targeted a software flaw that rendered seed values guessable, enabling attackers to derive private keys and sweep funds [1, 4]. In an initial 25-minute attack on July 31, attackers drained 594 BTC [1], valued at approximately $38 million at the time [2].
Losses continued to climb as subsequent waves of thefts were identified. Galaxy Research said they observed a third wave of thefts that pushed total losses to roughly $88.6 million worth of BTC [7]. This figure corresponds to approximately 1,367 BTC [8]. Other reports have placed the total stolen amount at $70 million [6].
"The flaw turned 'impossible to guess' seeds into guessable ones, allowing a rapid sweep of funds," a Galaxy Research analyst said [3].
Coinkite, the producer of the wallets, identified the specific hardware at risk. A Coinkite spokesperson said the company confirmed the Coldcard Mk3 model was affected and advised users to move their funds immediately [5].
The attackers utilized the randomness bug to bypass the security layers that normally protect the seed generation process. By predicting the seed, the attackers could recreate the wallet's master key without physical access to the device, a critical failure in the hardware's entropy source.
“The flaw turned 'impossible to guess' seeds into guessable ones, allowing a rapid sweep of funds.”
This incident highlights a critical failure in cryptographic entropy, the randomness required to make private keys secure. When a hardware wallet fails to generate truly random seeds, the security of the entire system collapses, regardless of whether the device is kept offline. For the broader cryptocurrency market, this emphasizes that hardware security is only as strong as the underlying software implementation of its randomness generators.


