Summary
A firmware integration error in Coldcard hardware wallets, persisting from March 2021 to July 2026, prevented the intended hardware random-number generator from contributing properly to seed creation. A MicroPython software fallback supplied predictable output, reducing effective search space from 128 bits to ~40 bits for affected Mk2/Mk3 models. Galaxy Research identified three attack waves draining 1,367.05 BTC (~$88.6M) from 4,585 addresses. The incident has triggered the largest surge in sub-1 BTC Bitcoin transfers since the FTX collapse.
Key Points
- Root cause: A March 2021 code change prevented the hardware RNG from contributing to seed creation. MicroPython software fallback supplied predictable output. Coinkite says it takes "full accountability."
- Affected models: Mk2/Mk3 firmware 4.0.1-4.1.9; Mk4/Mk5 pre-5.6.0; Q pre-1.5.0Q. Later models had extra secure-element entropy but still only ~72 bits vs intended 128 bits.
- Attack timeline: Wave 1 (July 30, 41 min): 1,082.65 BTC from 1,196 addresses. Wave 2 (July 31): 76.16 BTC from 1,478 addresses. Wave 3: 207.7 BTC from 1,912 addresses.
- User response: Sub-1 BTC daily transfers hit 39,600 BTC — highest since Nov 16, 2022 (39,900 BTC). CryptoQuant's Julio Moreno: "The Bitcoin plebs had not moved this amount of BTC in a day since the FTX collapse."
- Self-custody debate: Bloomberg's Eric Balchunas argues ETFs offer safer exposure. Casa CEO Nick Neuman counters that self-custody's distributed nature gives users time to react, estimating 10x more BTC was protected than stolen.
- Remediation: Firmware hotfixes available for all models. Users must generate new seed, verify backup, send test transaction, then move remaining balance. Seeds created with 50+ fair dice rolls not considered exposed by this issue alone.