Coldcard Wallet Flaw Sparks Alarm After $38 Million in Bitcoin Is Drained
Security researchers investigate a possible vulnerability in older Coldcard hardware wallets after nearly 600 Bitcoin is swept from hundreds of addresses, prompting urgent migration advice for affected users.

A major security scare has shaken the Bitcoin community after approximately 594.48 BTC, valued at around $38 million, was drained from hundreds of cryptocurrency wallets in what appears to be a coordinated attack. The incident has drawn attention to older versions of the Coldcard Mk3 hardware wallet, with manufacturer Coinkite warning users to immediately review their devices and migrate funds if they are running affected firmware.
According to Coinkite’s preliminary investigation, the potential issue affects Coldcard Mk3 devices using firmware version 4.0.1 through version 5.0.3, while newer models—including the Mk4, Mk5, and Coldcard Q—are not believed to be impacted. The company stressed that the investigation is ongoing and that there is currently no definitive proof linking the firmware issue directly to the large-scale Bitcoin theft. Nevertheless, it has advised users to act out of caution by creating a new wallet seed on an unaffected device and transferring their funds after verifying everything carefully.
The incident first came to light after a Coldcard user reported that their Bitcoin had been stolen from a wallet originally created on a Mk3 device in 2021. Security researchers then discovered a much larger pattern involving 1,324 unspent transaction outputs (UTXOs) that were consolidated through roughly 500 transactions within a very short period, suggesting an organized and automated operation rather than isolated thefts.
Blockchain security experts believe the attack may have exploited weak entropy during wallet seed generation. Entropy refers to the randomness used when creating a wallet’s private keys. If that randomness is insufficient, attackers may be able to predict or brute-force seed phrases far more easily than expected. Some researchers speculate that the weakness could stem from a software library, secure hardware component, or a specific firmware version used during wallet creation. However, these remain theories rather than confirmed findings.
Another observation that has attracted attention is that the stolen funds came primarily from single-signature Bitcoin wallets, with many of the addresses having remained inactive for years. Analysts noted that only certain address types appeared to be targeted, suggesting the attacker may have searched only a limited range of possible wallet derivation paths. If this hypothesis proves correct, additional wallets created under similar conditions could still be vulnerable until funds are moved.
Coinkite has emphasized that users who protected their wallet with a BIP-39 passphrase face significantly lower risk, as the additional passphrase creates another layer of security beyond the recovery seed itself. The company has promised to publish a full technical report once its investigation is complete and continues to work with independent Bitcoin security researchers to determine the exact cause of the incident.
The event serves as a reminder that even hardware wallets—widely regarded as the safest method of storing cryptocurrency—are not immune to security concerns. While no conclusive evidence has yet confirmed that the Coldcard firmware flaw caused the theft, the incident highlights the importance of keeping wallet firmware up to date, following manufacturer security advisories, and regularly reviewing cold storage practices.



