Blockchain analytics firm Chainalysis has linked a recently disclosed seed-generation flaw in Coldcard hardware wallets to over $38 million in stolen Bitcoin. The vulnerability, stemming from a firmware integration error, reduced the randomness used to create wallet seeds, potentially allowing attackers to reconstruct private keys. Independent analyses from Block and Galaxy Research confirmed the severity, with Galaxy estimating losses could be as high as $70.2 million. The manufacturer, Coinkite, has urged users to generate entirely new seeds, as firmware updates alone cannot fix previously created keys.
Investigators are uncovering a wider impact from the recently disclosed Coldcard seed-generation flaw, with blockchain analytics firm Chainalysis linking the vulnerability to more than $38 million in stolen Bitcoin. The latest findings build on Coinkite’s earlier security advisory, which warned that a firmware error reduced the randomness used to generate wallet seeds.
Independent analyses from Block and Galaxy Research also concluded that the flaw could allow attackers to reconstruct affected private keys under certain circumstances. According to Coinkite’s technical analysis, the issue stemmed from a firmware integration error that prevented the intended hardware random number generator from contributing to seed creation.
The affected process relied on a deterministic software fallback in MicroPython, which generated entropy from device information and timing data. Coinkite estimated that affected Coldcard Mk3 devices generated seeds with roughly 40 bits of effective entropy, while later Mk4, Mk5, and Q devices increased the effective search space to approximately 72 bits, still below the intended 128-bit security target.
Chainalysis described the incident as a “$38M+ Coldcard hack,” stating the attacker systematically targeted higher-value wallets before expanding to smaller balances. The company identified 1,196 affected UTXOs, including one worth approximately $1.8 million, and noted the attacker stole roughly $30 million in the first 10 minutes.
Separate analysis from Galaxy Research suggested the total losses may be even higher, identifying 1,196 addresses containing approximately 1,082.65 BTC, valued at around $70.2 million. The two estimates should not be treated as directly comparable, as they appear to measure different transaction sets.
Coinkite said the issue affects Mk3 firmware versions 4.0.1 through 4.1.9, while its updated advisory also includes seeds generated on Mk4, Mk5, and Q devices. The company stressed that installing updated firmware does not repair an existing seed, and affected users should generate a new seed and transfer funds only after verifying the replacement wallet.
