An attacker swept roughly 594 BTC, worth about $38 million in the report, from around 500 separate wallets between 01:31 and 01:56 UTC on Thursday, according to Unchained. The theft was traced to a flaw in how Coldcard generated wallet keys. Coldcard is an air-gapped hardware wallet built by Toronto-based Coinkite.
About 562 BTC has been consolidated into a single address. A wallet seed is supposed to be random and practically impossible to guess. But Block’s bitcoin engineering and security teams said in a Thursday report that a build setting caused Coinkite devices to build keys from a known unique identifier, timer state and call history instead of using a random number generator.
More than wallet seeds were affected
Block said the same flaw also affected Coldcard paper wallet private keys, seed-splitting masks and device cloning keys.
The firm said exposure depends on the firmware running on a device when the wallet was created, not on when the hardware was bought. A later firmware upgrade does not repair a seed that was already generated. The team also warned that anyone who exported an affected seed into another wallet still holds a weak seed.
Models and firmware in scope
According to Block, the issue affected Coldcard Mk3 devices using firmware v4.0.0, which was released in 2021. It also affected later models, including the Mk4, Q and Mk5.
In its advisory, Coinkite said, "the impact on Mk4, Mk5 and Q is not as severe but is still serious." The company told affected users that a BIP-39 passphrase leaves funds at minimal risk and recommended migrating to a seed generated on an unaffected device.
Traits shared by the drained wallets
Every drained wallet was single-signature and held more than 0.15 BTC. Many had been dormant for years. The coins spanned 2021 to 2026, a range the report said tracks the age of the bug almost exactly.
Disclosure follows another wallet security issue
The disclosure came days after Zilliqa halted native transactions over a flaw in the Ledger signing app it created. That issue allowed attackers to rebuild private keys from data already public on-chain. The report said that weakness had also gone unnoticed since 2019.

