“The Coldcard exploit is ongoing. Move Coldcard single-sig funds to safe locations immediately,” Galaxy Research said in a post on X (formerly Twitter) on August 2.
Scope: roughly $89 million and thousands of victim addresses
Researchers say an attack against the Coldwallet hardware wallet from Coinkite has already resulted in the theft of an estimated $89m. Galaxy Research tracked the initial wave of the exploit on July 30, reporting that attackers drained 1,082.65 Bitcoin — roughly $70m at the time — from 1,196 addresses during a 41-minute window and moved funds to four attacker-controlled addresses. The same research team said a second and third wave on August 1 pushed the total stolen to 1,367 Bitcoin (about $88.6m) and increased the victim address count to 4,385.
How the exploit worked, according to Block’s Bitcoin Engineering and Security team
Block’s Bitcoin Engineering and Security team reported on July 30 that the incident stemmed from exploitation of a firmware vulnerability dating back to 2021. Because of that bug, Coldwallet devices sometimes failed to use a hardware-based random-number generator (RNG) when creating wallet seeds (master keys). Instead, the device fell back to a deterministic generator that was not cryptographically secure.
Block’s team stated that the deterministic fallback made seed generation reproducible, meaning attackers could reproduce the keys offline and thereby derive private keys for affected wallets.

Built by Nubivance.
OSINTSights' secure edge-first architecture, AI content pipeline, and serverless ops are designed by Nubivance. We do this for clients too.
Talk to us →Coinkite’s technical guidance and affected models
Coinkite has released updated firmware for every affected model and release track and urged customers not to generate new seeds on affected models until they have installed the fix. The company spelled out the specific risk window for seed generation:
- “Funds controlled by a seed generated on Mk2 or Mk3 version 4.0.1 (March 2021) through 4.1.9 inclusive are at risk if the seed was created without at least 50 fair, independent, private dice rolls and the funded wallet is not protected by a strong, unique BIP-39 passphrase.”
- “Seeds generated on Mk4, Q and Mk5 before the fixed firmware releases are also affected, with about 72 bits of entropy rather than the expected 128 bits.”
Coinkite’s guidance thus ties the exposure to specific hardware models, firmware versions and to whether users supplemented seed generation with offline entropy (dice rolls) or protected the seed with a strong BIP-39 passphrase.
Attacker behavior, reporting, and ongoing activity
Galaxy Research described the July 30 activity as likely automated and traced funds to four attacker-controlled addresses during the initial wave. The firm later identified additional waves on August 1, and its head of firmwide research, Alex Thorn, suggested in a post on X that there may currently be a fourth wave of attacks underway.
Separately, Galaxy Research said it had reported about 600 addresses it believes to be holders of funds stolen from Coldcard-generated weak-entropy addresses to federal investigators, industry compliance firms, and cross-industry cyber investigators.
What this means for Coldcard users, federal investigators, and industry compliance firms
- Coldcard users: Galaxy Research and Coinkite both urged immediate action — update to the fixed firmware before generating new seeds, and move existing Coldcard single-signature funds to safe locations if they may have been generated in the affected windows.
- Federal investigators and cross-industry cyber investigators: Galaxy Research has reported approximately 600 suspected hacker-controlled addresses to federal investigators and cross-industry teams for follow-up and tracking.
- Industry compliance firms and security teams: the research team also notified industry compliance firms, providing address data and tracing that can be used to monitor movement of stolen funds and to support takedown or reporting efforts.
The facts recorded to date are stark: a firmware-era bug that allowed deterministic fallback RNGs to create reproducible seeds, rapid automated extraction of large sums across multiple waves, and public appeals from both researchers and the vendor for immediate remediation. Whether the attack has concluded remains uncertain — Galaxy Research warned the exploit is ongoing and flagged the possibility of further waves — and the practical, immediate task is the same for affected users and investigators: update firmware, move vulnerable single-signature funds, and follow the addresses already reported to authorities.




