Coldcard wallet exploit drained nearly 600 BTC from about 500 wallets in 25 minutes

Coldcard wallet exploit drained nearly 600 BTC from about 500 wallets in 25 minutes

N
News Editor
2026-07-31 12:47:32
A seed phrase exploit tied to Coldcard hardware wallets drained nearly 600 BTC, worth about $38 million, from roughly 500 dormant wallets in a 25-minute sweep, according to Protos. The funds were moved from 500 single-signature addresses into one destination address, and 562 of the 594 stolen BTC were still sitting there at the time of writing. Coinkite later said seed generation in the Mk3 wallet, and in updated versions after March 2021 beginning with version 4.0.1, may not have been random. Early statements from Coldcard said Mk3 devices were at risk, while Mk4, Q, and Mk5 were initially described as unaffected based on preliminary analysis. Separate reviews from Block, Bitcoin Core developer Gregory Sanders, and developer Stephen DeLorme pointed to a flaw in how firmware handled randomness checks, with some researchers also saying newer models may still carry a smaller version of the same bug. Coinkite and others said AI may have played a role in identifying or exploiting the vulnerability.

Nearly 600 BTC worth about $38 million was drained from roughly 500 dormant wallets yesterday in a seed phrase exploit targeting Coldcard hardware wallets, according to Protos.

The theft took about 25 minutes, moving bitcoin from 500 single-signature addresses into one address. Reports cited in the story said the exploit is likely to continue. CoinDesk reported that the affected BTC dated between 2021 and 2026, and much of it had sat dormant for years. Of the 594 BTC stolen, 562 remained in the same address at the time of writing.

Coinkite says seed generation may not have been random

Coldcard maker Coinkite confirmed hours after the exploit that seed generation in its Mk3 wallet, along with updated versions after March 2021 starting from version 4.0.1, may not have been random at all.

Coldcard initially said Mk3 devices were at risk and that Mk4, Q, and Mk5 were “not affected based on our early analysis.” In a July 31, 2026 post, the company said its first post covered the advisory and what users should do, while a second post set out the technical details, including what went wrong, why reviews missed it, the impact across Mk3, Mk4, Q, and Mk5, and what had been changed. The post also said the company was currently evaluating an Mk3 firmware release.

Protos described that as Coinkite’s updated analysis of the $38 million wallet exploit.

Block and other researchers found broader issues

Block, the payments company formerly known as Square, published a separate analysis that reached different conclusions. One of its team members, Max Guise, identified flaws spanning Coldcard models from Mk2 through Mk5.

Block traced the problem to a miswritten compile-time check. It said newer devices carried a smaller but still real version of the same flaw.

Coinkite says AI likely helped uncover the exploit

In its recent analysis, Coinkite said someone likely used AI to exploit the bug because Coldcard’s source code is open and public. The company said that even a few weeks before the attack, it had not found the issue despite using what it called “the best available AI models.”

Coinkite wrote, “Both attackers and defenders have the same AI tools, but today it did not help us, and only helped the bad guys.”

Coldcard wallet exploit drained nearly 600 BTC from about 500 wallets in 25 minutes 3

Cobra, the pseudonymous owner of the Bitcoin.org website, said they had a “very bad feeling AI was involved,” adding, “For whatever reason some addresses are only being partially drained despite the private key being compromised. Strange.”

Crypto developer Stephen DeLorme said he was able to use Claude Opus 5 to identify the Coldcard vulnerability after cloning the firmware repository. “All our software is insecure, and we’re painfully figuring that out in realtime with AI agents,” DeLorme said.

How the flaw worked

Bitcoin wallets need genuinely random numbers to create private keys that cannot be guessed. Coldcard firmware was supposed to pull that randomness from a hardware generator built into its STM32 chip.

According to Block, the codebase checked only whether a macro called MICROPY_HW_ENABLE_RNG was defined, not what value it held. Coinkite’s software build intentionally set that macro to zero. Because the character was set to zero rather than a variable symbol, the check was flawed.

Even so, the faulty check still passed during software operations. The firmware then fell back to Yasmarang, a MicroPython pseudo-random number generator that was never intended for real-world cryptographic protection.

Gregory Sanders reproduced the attack

Bitcoin Core developer Gregory Sanders said he reproduced the attack using setup button-press counts and confirmed its impact on Mk3 and Mk2 models. His reaction was blunt: “Sorry, this is the time to panic.”

Sanders first wrote, “confirmed. Mk2/3 vuln, I don’t think mk4 is but can’t be certain,” then followed up an hour later with, “mk4 is probably not much better.”

Public statements from Coinkite and Block do not fully align on how far the issue extends into newer devices. Still, the findings cited by Protos point to the same underlying problem: flaws in Coldcard’s randomness generation path gave attackers a way to compromise wallets at scale.

This article was originally published by Bit.Fan. For more cryptocurrency news and market insights, visit www.bit.fan.
860

Disclaimer:

The market information, project data, and third-party content displayed on this platform are for industry information sharing only and do not constitute any form of investment advice or return commitment.

Cryptocurrency trading carries high risks. Users should fully assess their risk tolerance and make independent decisions. All profits, losses, and legal responsibilities are borne by the users themselves.