Skip to content
3 August 2026

Bitcoin thefts surge: Coldcard users warned of critical security flaw

A new wave of coordinated thefts is targeting Coldcard Bitcoin hardware wallets, with researchers identifying 218 transactions impacting 462 potential victim addresses. The flaw has led to significant Bitcoin losses, prompting urgent security warnings.

Bitcoin thefts surge: Coldcard users warned of critical security flaw

The Bitcoin community is on high alert as a new wave of coordinated thefts targets Coldcard hardware wallets. Just days after the initial attacks on Thursday, researchers have identified a surge in suspicious transactions, raising concerns about the security of affected devices.

In a recent post on X, Alex Thorn head of research at Galaxy reported 218 transactions affecting 462 potential victim addresses. These transactions moved approximately 388.9 Bitcoin (BTC) with an average of 13.8 sweeps per block about 45 times the rate observed before the incident. The pattern suggests a targeted attack on vulnerable Coldcard devices.

Coldcard flaw leads to significant Bitcoin losses

The latest estimates indicate that over 1,100 wallets have been impacted, with losses amounting to $90 million in Bitcoin. The flaw, which was previously undetected, causes affected devices to generate wallet seeds with less entropy than intended, making them vulnerable to theft.

The issue stems from a firmware flaw that was disclosed after the initial wave of attacks. The flaw was traced back to a firmware integration error that routed seed generation to a deterministic software pseudorandom number generator (PRNG) instead of the intended hardware random number generator (RNG). This error significantly weakened the security of the generated seeds.

Technical details of the flaw

The flaw was linked to Coldcard’s production config, which defines MICROPY_HW_ENABLE_RNG as zero. This configuration error caused the build to rely on MicroPython’s Yasmarang fallback, which was initialized from the chip’s unique ID and timer registers and collected no fresh entropy after initialization. As a result, the effective entropy was reduced to approximately 40 bits on the Mk3 and 72 bits on the Mk4, Mk5, and Q models, far below the intended 128 bits for a 12-word BIP-39 seed.

Researchers at Block explained that an attacker who can determine or sufficiently constrain the device UID, timer state, and prior RNG-call history can reproduce candidate output streams offline without accessing the device. Candidate seeds can then be checked by deriving their addresses and comparing them with public blockchain data.

Urgent security measures for affected users

Affected users are urged to take immediate action to secure their funds. Coinkite, the manufacturer of Coldcard, has released emergency firmware for all affected models. However, installing the new firmware does not repair an existing seed. Users with exposed seeds are advised to generate a new one on patched firmware and move their coins to a secure wallet.

Restoring the old seed to updated firmware or another wallet carries the weakness forward. Therefore, it is crucial to generate a completely new seed and migrate funds to the new wallet. Users are also advised to add at least 50 fair, independent, private dice rolls during seed generation to supplement the device’s hardware entropy.

Multisig setups can provide additional security, but only when the quorum is not built entirely from affected devices. TAPSIGNER, OPENDIME, and SATSCARD are unaffected by this vulnerability, as they use different codebases.

The disclosure follows Coinspect’s Ill Bloom research in early July, which identified a separate weak-PRNG flaw in older software wallets. This flaw has been tied to more than $5 million drained from addresses across various blockchains since May.

As the situation develops, researchers continue to monitor the on-chain activity and report suspected attacker-controlled addresses to federal investigators, compliance firms, and cybersecurity investigators. Users are encouraged to stay vigilant and take proactive steps to protect their Bitcoin holdings.

Author

Florence Wright

Florence Wright, Glasgow native with an editorial-minimal aesthetic, rerouted a social feed to live-cover a Pollok Park remembrance event, prioritising human detail over algorithmic reach. Promotes clarity, humane framing and local resonance; keeps an archive of Polaroids from neighbourhood gatherings as a personal emblem.