Galaxy Research has linked an exploit of Coldcard hardware wallets to the theft of 1,596 Bitcoin from approximately 7,300 addresses across three confirmed attack waves. A suspected fourth wave, which remains unconfirmed, could raise total losses to roughly 2,055 BTC, valued at nearly $130 million. The vulnerability stemmed from a firmware bug that used a weak pseudo-random seed generator instead of hardware-based randomness.
Galaxy Research published its findings on Monday, stating it has high confidence that 1,596 BTC has been stolen. The figure is based on confirmed losses from three distinct attack waves and 14 smaller security incidents.
The research firm estimates the potential total could reach nearly $130 million if a suspected fourth wave is confirmed. An additional 448.7 BTC is believed stolen from roughly 709 probable victim addresses.
Galaxy has not included the fourth wave in its confirmed total due to a lack of verification from affected wallet owners. The firm is awaiting more victims to confirm the related addresses.
Blockchain activity suggests one attacker likely accounted for a substantial share of the suspected fourth wave. Galaxy expressed medium-high confidence in that assessment.
The bug affects seeds generated by Coldcard Mk3, Mk4, Mk5, and Coldcard Q models. Coinkite traced the problem to work completed in March 2021 during the integration of a new cryptographic library.
The firmware used a deterministic pseudo-random generator from MicroPython for wallet seeds instead of the hardware-backed random number generator. The hardware generator remained operational in other firmware parts.
Coinkite estimated that vulnerable devices could generate between 40 and 72 bits of entropy, far below the intended 128 bits. Galaxy advised affected users to transfer funds to safer addresses and create entirely new wallet seeds on patched devices.
