A five-year-old firmware flaw in Coldcard Bitcoin hardware wallets has grown into one of the largest self-custody exploits in cryptocurrency history, with total stolen funds reaching approximately 1,367 BTC worth around $89 million across three distinct attack waves between July 30 and August 2.
Galaxy Research mapped the full scope of the theft, tracing the attacker sweep of 4,585 addresses in a 41-minute window on July 30. The exploit did not require physical access to any device. Instead, a coding change introduced on March 1, 2021 caused Coldcard Mk3 firmware to silently fall back to a weak software-based random number generator instead of the hardware RNG, collapsing the effective entropy search space from 128 bits to roughly 40 bits.
Block Bitcoin Engineering team first identified the predictable RNG fallback. Coinkite, the Canadian manufacturer, confirmed the vulnerability and urged all affected users to generate new recovery seeds and move their funds immediately. The attacker exploited this weakness offline, regenerating likely seeds, deriving addresses, and sweeping those that held Bitcoin.
The theft unfolded in escalating waves. Chainalysis reported the attacker targeted the largest balances first, pulling over $30 million in the opening ten minutes. The first wave on July 30 drained roughly 594 BTC from about 500 wallets. A second wave identified by Galaxy pushed the total to 1,158 BTC from 2,673 addresses, and a third wave on August 2 brought the cumulative figure to 1,367 BTC across 4,585 addresses.
More than 77,000 BTC moved from older wallets as Coldcard users raced to secure their holdings, creating the largest Bitcoin on-chain movement since the FTX collapse and significantly distorting market signals across key indicators. CryptoSlate flagged that the surge complicated bearish readings from metrics typically used to assess network health and investor sentiment.
Analysts at Cantor Fitzgerald and FRNT Financial said the exploit could paradoxically boost demand for regulated Bitcoin exposure products such as spot ETFs. The argument is that the breach undermines confidence in self-custody solutions and may push some investors toward institutional custodians and exchange-traded products where counterparty risk is more transparent.
None of the stolen funds have been moved since the final wave, which Galaxy called unusual for a theft of this magnitude. The firm offered two possible explanations: the operator is waiting for scrutiny to fade, or lacks a viable method to launder a sum this visible on public ledgers. The unresolved movement of nearly $90 million continues to weigh on market confidence as Bitcoin trades near $64,000.
The incident has reignited debate about hardware wallet security and the tradeoffs of self-custody. BlockTower Capital founder Ari Paul wrote on X that the breach proves there is simply no way to fully secure crypto assets, a stark assessment that resonated across the industry as users and developers grapple with the implications for decentralized finance and personal security practices.
Sources: TheStreet, CoinDesk, CryptoSlate
discussion