Crypto

Coldcard Bitcoin hack losses could reach $114 million, researchers say

A possible fourth sweep tied to flawed Coldcard-generated keys could lift losses to $114 million, though the latest wave remains unconfirmed.

Dev Ramirez

By Dev Ramirez · Crypto Correspondent

· 3 min read

Coldcard Bitcoin hack losses could reach $114 million, researchers say
Photo: Decrypt

Coldcard Bitcoin hack losses could approach $114 million if a newly identified set of wallet sweeps is confirmed, according to Galaxy Research tracking reported by CoinDesk. For Bitcoin holders, the key distinction is that the first three waves were observed on-chain, while the possible fourth wave was identified from transaction patterns and had no direct victim reports at the time.

CoinDesk reported that the first three waves, beginning July 30, moved 1,367 bitcoin from 4,585 addresses. A potential fourth wave would bring the total to about 1,816 bitcoin from more than 5,200 addresses, valued near $114 million at recent prices.

Alex Thorn, head of firmwide research at Galaxy Research, said the latest finding was published as a warning while transactions remained pending, despite the lack of direct confirmation from affected holders. That makes the $114 million figure a provisional estimate, rather than a confirmed tally of stolen funds.

What caused the Coldcard Bitcoin wallet sweeps?

The reported weakness traces to a March 2021 Coldcard firmware build. According to CoinDesk, the software used a predictable software randomizer to create wallet seeds instead of the device chip's hardware randomizer.

A seed is the secret starting point used to generate a wallet's private keys, which control access to bitcoin. If the process that creates a seed has too little randomness, someone who identifies the limited range of possible outcomes can reproduce keys offline, without possessing the physical device.

The first sweep on July 30 took 1,083 bitcoin from 1,196 addresses in 41 minutes, CoinDesk reported. Subsequent waves expanded the number of addresses involved. The observed pattern suggested the exposure involved single-key seeds rather than multisignature wallets, which require more than one key to authorize a transaction.

Could holders stop an unconfirmed sweep?

Some transactions in the possible fourth wave used Bitcoin's replace-by-fee setting, CoinDesk reported. Replace-by-fee allows an unconfirmed transaction to be replaced with another transaction that pays a higher network fee.

In practical terms, a holder who spots a pending unauthorized transfer in the mempool, Bitcoin's queue of transactions awaiting confirmation, may have a limited chance to move the coins first by broadcasting a replacement transaction with a higher fee. That option applies only before the original transaction is confirmed and does not establish that every affected holder can recover funds.

CoinDesk said Coldcard maker Coinkite released emergency firmware for affected models and advised users who created a seed with the flawed software to move funds to an address generated from a fresh seed. The reported guidance is narrowly tied to seeds made under the affected software, not to every Coldcard device or firmware version.

The episode is a reminder that a hardware wallet's physical security is only part of the picture. The quality of the software used to generate its keys also determines whether a holder's bitcoin can remain under their control.

This story draws on original reporting from Decrypt.

More from Crypto

All Crypto