Coldcard Wallet Bug Linked to $70 Million Bitcoin Theft

Published:
2 MIN READ

The allegation centers on a weakness in how certain Coldcard firmware generated the random entropy used to create wallet seeds. Coinkite, the maker of Coldcard, has published a seed generation warning for the Mk3 device describing conditions under which seed randomness could be compromised.

An alleged bug in the Coldcard hardware wallet has been linked to a reported $70 million theft of Bitcoin, raising fresh questions for self-custody users about the security of the devices they rely on to hold private keys offline.

What Is Being Alleged About the Coldcard Wallet Bug

The allegation centers on a weakness in how certain Coldcard firmware generated the random entropy used to create wallet seeds. Coinkite, the maker of Coldcard, has published a seed generation warning for the Mk3 device describing conditions under which seed randomness could be compromised. For related coverage, see Coldcard Hack Reportedly Hit 1,000+ Bitcoin Addresses.

Security researchers at Block detailed a related issue, describing a predictable RNG fallback and 32-bit reseed in Coldcard firmware. A predictable random number generator can, in principle, make the resulting private keys guessable.

The specific $70 million figure remains a reported claim rather than a confirmed, independently traced on-chain total. Readers should treat the link between the firmware weakness and any single theft as alleged until vendor disclosures and blockchain evidence establish the exact scope.

How the Reported Issue Could Affect Bitcoin Holders

Coldcard is used specifically for Bitcoin storage and cold self-custody, so a flaw in seed generation strikes at the core function of the device. Coinkite’s own entropy technical backgrounder explains how the device is meant to combine multiple randomness sources to produce a secure seed.

The users most exposed are those who generated a seed on affected firmware without additional entropy safeguards. Holders who added their own dice-roll entropy or generated seeds outside the vulnerable conditions may not be affected, which is why the reported risk should not be read as broad, confirmed impact across all Coldcard owners.

Coverage of the incident has grown alongside reports that a Coldcard hack reportedly hit more than 1,000 Bitcoin addresses, and that a 2021 firmware flaw has continued to drain wallets over an extended period.

Why This Story Matters for the Bitcoin Wallet Market

High-profile wallet security incidents move quickly through the market and can pressure trust in hardware wallet brands even before technical details are fully confirmed. The scrutiny has intensified as a third wave of Coldcard-linked losses put hardware wallet security in focus.

Galaxy Research flagged the situation to its followers on X, drawing attention to the firmware entropy concerns among Bitcoin holders, in a post on the platform.

Coinkite has responded by urging affected users to move their Bitcoin while the situation remains active. The final picture, including the verified loss total and the precise firmware versions involved, will depend on further vendor disclosures and independent on-chain analysis.

Disclaimer: This article is for informational purposes only and does not constitute financial or investment advice. Cryptocurrency and digital asset markets carry significant risk. Always do your own research before making decisions.

Article Topics