BTC $71,807
2026 Bull Run Is Building Start trading with 5% OFF all fees
Sign Up Now
BTC $71,807
Bull Run 2026 | 5% Off Fees Open your Binance account today
Sign Up
HomeNewsColdcard seed flaw linked to $38M+ in stolen Bitcoin, say analysts

Coldcard seed flaw linked to $38M+ in stolen Bitcoin, say analysts

-

Blockchain analytics firm Chainalysis has linked a recently disclosed seed-generation flaw in Coldcard hardware wallets to over $38 million in stolen Bitcoin. The vulnerability, stemming from a firmware integration error, reduced the randomness used to create wallet seeds, potentially allowing attackers to reconstruct private keys. Independent analyses from Block and Galaxy Research confirmed the severity, with Galaxy estimating losses could be as high as $70.2 million. The manufacturer, Coinkite, has urged users to generate entirely new seeds, as firmware updates alone cannot fix previously created keys.


Investigators are uncovering a wider impact from the recently disclosed Coldcard seed-generation flaw, with blockchain analytics firm Chainalysis linking the vulnerability to more than $38 million in stolen Bitcoin. The latest findings build on Coinkite’s earlier security advisory, which warned that a firmware error reduced the randomness used to generate wallet seeds.

- Advertisement -
Ad
Altseason Is Loading. Don't watch from the sidelines.
SOL $90.51
DOGE $0.0963
LINK $9.02
SUI $1.00
5% off fees when you sign up
Start Trading

Independent analyses from Block and Galaxy Research also concluded that the flaw could allow attackers to reconstruct affected private keys under certain circumstances. According to Coinkite’s technical analysis, the issue stemmed from a firmware integration error that prevented the intended hardware random number generator from contributing to seed creation.

The affected process relied on a deterministic software fallback in MicroPython, which generated entropy from device information and timing data. Coinkite estimated that affected Coldcard Mk3 devices generated seeds with roughly 40 bits of effective entropy, while later Mk4, Mk5, and Q devices increased the effective search space to approximately 72 bits, still below the intended 128-bit security target.

Chainalysis described the incident as a “$38M+ Coldcard hack,” stating the attacker systematically targeted higher-value wallets before expanding to smaller balances. The company identified 1,196 affected UTXOs, including one worth approximately $1.8 million, and noted the attacker stole roughly $30 million in the first 10 minutes.

Separate analysis from Galaxy Research suggested the total losses may be even higher, identifying 1,196 addresses containing approximately 1,082.65 BTC, valued at around $70.2 million. The two estimates should not be treated as directly comparable, as they appear to measure different transaction sets.

Coinkite said the issue affects Mk3 firmware versions 4.0.1 through 4.1.9, while its updated advisory also includes seeds generated on Mk4, Mk5, and Q devices. The company stressed that installing updated firmware does not repair an existing seed, and affected users should generate a new seed and transfer funds only after verifying the replacement wallet.

Most Popular

Ad
Pay Less on Every Trade. For Life.
$10K/mo volume Save $60/yr
$50K/mo volume Save $300/yr
$100K/mo volume Save $600/yr
5% off all trading fees when you sign up
Claim Your Discount