Coldcard Bitcoin Theft Reaches $88 Million as Wallet Drains Continue
Bitcoin stolen from wallets linked to a Coldcard firmware flaw reached about 1,367 BTC, worth nearly $89 million, after attackers carried out several waves of transactions. Galaxy Research tracked funds leaving more than 4,500 Bitcoin addresses.
The attacks have continued despite warnings from Coldcard maker Coinkite. The company released fixed firmware and told affected users to create new seeds and move their funds.
Attackers Drain 4,585 Wallets in Three Waves
The first known wave removed about 594 BTC from roughly 500 addresses. Later transactions targeted more wallets, raising observed losses to 1,367 BTC across 4,585 addresses.
The latest attacks focused on smaller balances and used more complex transaction patterns. Researchers said the changes made the stolen funds harder to trace than those taken during the first sweep.
Further suspicious transactions were still appearing after the $88 million estimate was published. Galaxy Research later identified another wave involving about 388.9 BTC taken from 462 addresses, showing that exposed wallets remained under threat.
Firmware Flaw Weakened Wallet Seeds
The security issue influenced how some Coldcard devices generated wallet seed phrases. Seeds created with affected firmware did not contain enough randomness. This allowed attackers to recreate private keys and move the Bitcoin linked to them.
Coinkite said Mk2 and Mk3 firmware versions 4.0.1 through 4.1.9 were affected. Seeds created on Mk4, Mk5 and Coldcard Q devices before the fixed releases were also at risk. However, Coinkite said the issue was less serious on those models.
Coinkite warned that updating the device does not repair a seed that was created with affected firmware. The company said:
“A strong passphrase reduces the immediate exposure, but it does not repair the affected seed.”
Coinkite Tells Users to Move Bitcoin
Fixed firmware is now available for all affected Coldcard models and release tracks. Users must install the correct update before generating a replacement seed, as standard and Edge firmware have separate version numbers.
Coinkite recommends creating a new seed, checking the receiving address and sending a small test transaction before moving the remaining balance. TAPSIGNER, OPENDIME, and SATSCARD products are not affected because they use different code.
Bitcoin held in wallets created with affected firmware could still be stolen until users move it to a new seed.