Key facts
- Over 1,000 Bitcoin, valued at approximately $70 million, were stolen from 1,196 Coldcard wallets.
- A firmware flaw in specific Coldcard models allowed attackers to reconstruct private keys by making seed phrases enumerable.
- The attack occurred over a 41-minute window on July 30.
- The stolen funds have not been moved and are held in four addresses.
- Owners of affected wallets cannot reliably determine if their seeds were generated on vulnerable firmware.
- The vulnerability affected Coldcard Mk2, Mk3, Mk4, Q, and Mk5 models.
More than 1,000 Bitcoin, valued at approximately $70 million, were stolen from 1,196 Coldcard hardware wallets in a 41-minute period on July 30. Researchers discovered that a firmware flaw in certain Coldcard models allowed attackers to computationally enumerate seed phrases, enabling them to reconstruct private keys without ever physically interacting with the devices. This exploit is significant because it bypasses the core security promise of hardware wallets, which is to keep private keys isolated from online threats. The stolen funds are currently held in four addresses and have not been moved. Security firms warn that owners of affected wallets cannot definitively determine if their seeds were generated on vulnerable firmware, suggesting further attacks are possible. Investigators are tracing the attacker using logs from a blockchain data provider. Coinkite has issued warnings for Mk3 owners and stated newer devices are unaffected, while reports indicate Mk2, Mk4, Q, and Mk5 models are also in scope. The attacker reportedly used a paid account with a blockchain data provider to query source addresses during the theft.
