Researchers at Galaxy Digital say about $70 million has been stolen due to an exploit in the popular Bitcoin wallet Coldcard.
The attack was enabled by a firmware bug that dramatically reduced the randomness of how the wallet creates its secret recovery phrase.
According to Galaxy, the vast majority of the funds were stolen in less than an hour.
“While new attacks are likely to occur if users do not migrate their funds out of affected Coldcard-generated addresses, the initial attack is identifiable onchain. Note that this analysis may not be complete, but it represents our best-efforts attempt at scoping the initial impact…
The full event spans six blocks and 41 minutes. Three intervening blocks contain no sweep activity at all, suggesting the transactions were broadcast in batches rather than streamed…
The loss profile is dominated by sub-1 $BTC addresses in count, but by 1-50 $BTC addresses in value. This is the shape of individual self-custody, not institutional or exchange holdings.”
Coinkite, the company behind Coldcard, says it takes full accountability for the firmware bug and has apologized to affected users.
The company has released emergency firmware updates for all affected models: version 4.2.0 or later for Mk3, 5.6.0 or later for Mk4 and Mk5, and 1.5.0Q or later for the Coldcard Q.
These updates remove the vulnerable software fallback path and ensure new seeds use the intended hardware true random number generator.
Critically, a firmware update alone does not secure existing seeds. Users must generate an entirely new recovery phrase on the fixed firmware and migrate their $BTC.