Skip to content
Active Currencies: 18,090
Market Cap: $2.246T
Bitcoin Dominance: 56.26%
24h Market Cap Change: $-2.10

Coldcard seed flaw linked to $38M Bitcoin theft as loss estimates continue to rise

Coldcard’s flawed randomness process left certain wallet seeds vulnerable, affecting hundreds of Bitcoin wallets.

Coldcard seed flaw linked to $38M Bitcoin theft as loss estimates continue to rise

Investigators are uncovering a wider impact from the recently disclosed Coldcard seed-generation flaw, with blockchain analytics firm Chainalysis linking the vulnerability to more than $38 million in stolen Bitcoin.

The latest findings build on Coinkite’s earlier security advisory, which warned that a firmware error reduced the randomness used to generate wallet seeds. 

Independent analyses from Block and Galaxy Research also concluded that the flaw could allow attackers to reconstruct affected private keys under certain circumstances.

Firmware error weakened seed generation

According to Coinkite’s technical analysis, the issue stemmed from a firmware integration error that prevented the intended hardware random number generator from contributing to seed creation.

Instead, the affected process relied on a deterministic software fallback in MicroPython, which generated entropy from device information and timing data rather than from a cryptographically secure hardware source.

Coinkite estimated that affected Coldcard Mk3 devices generated seeds with roughly 40 bits of effective entropy.

Later Mk4, Mk5, and Q devices incorporated additional entropy from their secure elements, increasing the effective search space to approximately 72 bits. However, this remained below the intended 128-bit security target.

Researchers at Block independently reached similar conclusions, stating that the flaw could allow attackers to reconstruct private keys under certain conditions.

Chainalysis traces more than $38 million in stolen Bitcoin

Chainalysis described the incident as a “$38M+ Coldcard hack”, saying the attacker systematically targeted higher-value wallets before expanding to smaller balances.

The company identified 1,196 affected UTXOs, including one worth approximately $1.8 million.

According to its analysis, the attacker stole roughly $30 million in the first 10 minutes, then swept around 500 wallets in just 25 minutes.

Chainalysis said it continues to monitor the attacker’s wallets and associated consolidation addresses as additional victims are identified.

Different firms estimate different losses

Separate analysis from Galaxy Research suggested the total losses may be even higher.

Galaxy identified 1,196 addresses containing approximately 1,082.65 BTC, valued at around $70.2 million, that were drained over a 41-minute period.

The two estimates should not be treated as directly comparable.

Chainalysis and Galaxy appear to be measuring different transaction sets and using different methodologies, meaning the higher estimate does not necessarily replace the earlier $38 million figure.

Coinkite urges users to replace affected seeds

Coinkite said the issue affects Mk3 firmware versions 4.0.1 through 4.1.9, while its updated advisory also includes seeds generated on Mk4, Mk5, and Q devices before the latest firmware fixes.

The company stressed that installing updated firmware does not repair an existing seed.

Instead, affected users should first update their device, generate a new seed, and transfer funds only after verifying the replacement wallet.


Final Summary

  • Chainalysis linked more than $38 million in stolen Bitcoin to private keys believed to have been generated by vulnerable Coldcard devices. At the same time, Galaxy Research estimated a larger set of affected addresses worth about $70.2 million.
  • Coinkite says affected users should generate entirely new wallet seeds because firmware updates alone cannot repair previously created keys.

 

Disclaimer: AMBCrypto's content is meant to be informational in nature and should not be interpreted as investment advice. Trading, buying or selling cryptocurrencies should be considered a high-risk investment and every reader is advised to do their own research before making any decisions.

Adewale Olarinde

Journalist

Adewale Olarinde is a crypto journalist and data-driven storyteller with a Master’s degree in International Relations. He covers digital assets, markets, and policy with a focus on clarity and context. Outside of work, he’s a lifelong Manchester United supporter and a big music lover.

AMBCrypto was founded in 2018 with a mission to simplify and bring the latest blockchain and cryptocurrency news to our readers. We have quickly grown into the digital news source for an emerging generation of cryptocurrency enthusiasts, reaching more than a million readers on a monthly basis, across the globe.