$70M Bitcoin Stolen as Coinkite Confirms All Coldcard Models Vulnerable
A firmware flaw exposing private keys has triggered a $70 million theft from Coldcard wallets, prompting urgent warnings for investors to shift funds to secure custody.
Over $70 million in Bitcoin has been stolen from Coldcard hardware wallets after manufacturer Coinkite confirmed a critical firmware vulnerability affects all of its device models. The thefts, which initially drained $35 million from Mk3 devices before spreading, have triggered urgent warnings from institutional researchers for users to immediately relocate their funds.
The breach stems from a bug introduced in March 2021 in Coldcard Mk3 devices running firmware version 4.0.1 and above. Instead of utilizing the hardware's true random number generator, the system fell back to a weak software pseudorandom number generator during seed creation. This flaw made the private keys of single-signature wallets highly predictable, particularly for users who did not manually add complexity using dice rolls or a BIP-39 passphrase.
Tracing the stolen funds has revealed that the attacker leveraged mainstream crypto infrastructure to execute the heist. Clay Garrett, an engineer at payments firm Block, noted on X that investigators identified an unusual sweep pattern matching a specific workflow. “That pattern led us to a hypothesis that has since been confirmed: the operator used a paid account at a well-known blockchain-services provider to query the source addresses and perform other related activity during the sweeps,” Garrett said, adding that authorities have been notified.
The exploitation of a legitimate blockchain services platform highlights the dual-use nature of crypto infrastructure, where tools designed for compliance can facilitate large-scale theft. Galaxy Digital’s research division warned that the attack’s on-chain signature is subtle. “The pattern tells us these were all the same attacker — it does not capture the attack itself, which looks the same as if a coin owner chose to move coins,” the firm stated.
For market participants holding Bitcoin on single-signature Coldcard setups, the risk of further losses remains acute as engineers continue to identify compromised addresses. Galaxy Digital explicitly advised that Bitcoiners “move funds out of single-signature Coldcard addresses and into secure custody,” underscoring a sudden erosion of trust in a hardware wallet brand long favored by security-conscious investors.