Coldcard bitcoin flaw tied to estimated $38 million BTC drain
Coinkite says a seed-generation error put some Coldcard wallets at risk, with losses estimated at 594 BTC across roughly 500 wallets.
By Dev Ramirez · Crypto Correspondent
· 3 min read
A Coldcard bitcoin flaw has been linked to an estimated 594 BTC theft, worth about $38 million, after wallet maker Coinkite warned that some devices created weaker-than-intended recovery seeds. For investors who self-custody crypto, the incident is a reminder that keeping coins off an exchange still depends on the wallet’s code working as designed.
Coinkite published a security advisory for its Coldcard Mk3 and a separate technical explanation on Thursday. The company said a build error caused some wallet seeds to come from a software fallback instead of the device’s hardware random-number generator.
A seed is the master recovery phrase for a crypto wallet. If that seed is created with too little randomness, an attacker may be able to reduce the number of possible phrases they need to test and eventually reach the wallet’s funds.
What happened in the Coldcard bitcoin flaw?
The weakness was exploited early Friday, according to reporting cited by CoinDesk, which estimated the loss at 594 BTC, or roughly $38 million. The funds were taken from about 500 wallets in a 25-minute sweep, and 562 BTC were later gathered into a single Bitcoin address, according to blockchain data referenced in the report.
Coinkite said in a post on X that users who generated a seed on a Coldcard Mk3 after firmware version 4.0.1 may have funds at risk. The company urged affected users to read its advisory and move funds carefully.
In that same public notice, Coinkite said its early analysis found that Mk4, Q and Mk5 devices were not affected. Coinkite’s broader warning also said a firmware update does not fix a seed that was already created with weak randomness, meaning the key step for affected users is creating a new secure seed and moving funds to it.
Why does Coinkite think AI was involved?
Coinkite said it believes an attacker may have used artificial intelligence to review older versions of its open-source firmware and find the bug. The company said it had run its own AI review of the same code weeks earlier and did not find the issue.
That claim is Coinkite’s assessment, not a confirmed identification of the attacker. The company has not named who carried out the exploit in the information available, and the reported blockchain activity only shows where funds moved after the wallets were emptied.
Why a hardware wallet bug can still cost real money
A hardware wallet is meant to keep private keys offline, away from internet-connected devices that are easier to compromise. Cold storage reduces many common risks, but it cannot protect a wallet if the secret phrase itself was generated in a predictable way.
The failure described by Coinkite sits at the start of the custody process: seed creation. Once a weak seed exists, later software fixes do not change the private keys tied to that phrase. That is why Coinkite’s warning focuses on migration, not just updating firmware.
The estimated size of the loss makes the bug one of the more serious wallet-security incidents disclosed in recent crypto history. It also puts open-source security under a harsher spotlight: public code can be reviewed by defenders, but Coinkite now says attackers may have used AI tools to search that same code faster than humans could.
This story draws on original reporting from Decrypt.