A critical flaw in Coldcard hardware wallets has been linked to the theft of roughly 594 BTC — worth close to $38 million — from around 500 self-custody wallets in a rapid sweep lasting under 30 minutes.
The vulnerability traces back to firmware version 4.0.0, released by Canadian manufacturer Coinkite in March 2021. Rather than pulling from the device’s dedicated hardware random number generator, affected units silently fell back to a software-based key generation process built on non-secret chip data — making the resulting wallet seeds far easier to predict than intended. Analysis from blockchain security firm Chainalysis found the attacker targeted higher-value wallets first, pulling an estimated $30 million in the opening ten minutes before expanding to smaller balances across nearly 1,200 affected addresses. Separate research from Galaxy Research put the total scope even higher, estimating over $70 million drained across a 41-minute window.
Coinkite has confirmed the issue affects wallets that generated seeds on Mk3 devices running firmware 4.0.1 or later, while newer Mk4, Mk5 and Q models appear unaffected. A firmware patch has already shipped, but the company is warning that updating alone won’t protect existing funds — anyone who generated a seed during the vulnerable window needs to create an entirely new wallet and migrate their holdings.
The incident has reignited debate around the reliability of self-custody, given that affected users followed standard best practice: buying a reputable air-gapped device, never exposing seed phrases to a networked machine, and holding funds untouched for years. Some analysts suggest the episode could nudge more investors toward regulated custodians or spot Bitcoin ETFs rather than managing private keys directly. Bitcoin’s price showed little reaction to the news.










