The Bitcoin community is on high alert as a new wave of coordinated thefts targets Coldcard hardware wallets. Just days after the initial attacks on Thursday, researchers have identified a surge in suspicious transactions, raising concerns about the security of affected devices.
In a recent post on X, Alex Thorn head of research at Galaxy reported 218 transactions affecting 462 potential victim addresses. These transactions moved approximately 388.9 Bitcoin (BTC) with an average of 13.8 sweeps per block about 45 times the rate observed before the incident. The pattern suggests a targeted attack on vulnerable Coldcard devices.
Coldcard flaw leads to significant Bitcoin losses
The latest estimates indicate that over 1,100 wallets have been impacted, with losses amounting to $90 million in Bitcoin. The flaw, which was previously undetected, causes affected devices to generate wallet seeds with less entropy than intended, making them vulnerable to theft.
The issue stems from a firmware flaw that was disclosed after the initial wave of attacks. The flaw was traced back to a firmware integration error that routed seed generation to a deterministic software pseudorandom number generator (PRNG) instead of the intended hardware random number generator (RNG). This error significantly weakened the security of the generated seeds.
Technical details of the flaw
The flaw was linked to Coldcard’s production config, which defines MICROPY_HW_ENABLE_RNG as zero. This configuration error caused the build to rely on MicroPython’s Yasmarang fallback, which was initialized from the chip’s unique ID and timer registers and collected no fresh entropy after initialization. As a result, the effective entropy was reduced to approximately 40 bits on the Mk3 and 72 bits on the Mk4, Mk5, and Q models, far below the intended 128 bits for a 12-word BIP-39 seed.
Researchers at Block explained that an attacker who can determine or sufficiently constrain the device UID, timer state, and prior RNG-call history can reproduce candidate output streams offline without accessing the device. Candidate seeds can then be checked by deriving their addresses and comparing them with public blockchain data.
Urgent security measures for affected users
Affected users are urged to take immediate action to secure their funds. Coinkite, the manufacturer of Coldcard, has released emergency firmware for all affected models. However, installing the new firmware does not repair an existing seed. Users with exposed seeds are advised to generate a new one on patched firmware and move their coins to a secure wallet.
Restoring the old seed to updated firmware or another wallet carries the weakness forward. Therefore, it is crucial to generate a completely new seed and migrate funds to the new wallet. Users are also advised to add at least 50 fair, independent, private dice rolls during seed generation to supplement the device’s hardware entropy.
Multisig setups can provide additional security, but only when the quorum is not built entirely from affected devices. TAPSIGNER, OPENDIME, and SATSCARD are unaffected by this vulnerability, as they use different codebases.
The disclosure follows Coinspect’s Ill Bloom research in early July, which identified a separate weak-PRNG flaw in older software wallets. This flaw has been tied to more than $5 million drained from addresses across various blockchains since May.
As the situation develops, researchers continue to monitor the on-chain activity and report suspected attacker-controlled addresses to federal investigators, compliance firms, and cybersecurity investigators. Users are encouraged to stay vigilant and take proactive steps to protect their Bitcoin holdings.



