Coldcard Firmware Flaw Triggers $100M Bitcoin Heist, Sparking Self-Custody Crisis
Key Takeaways
A five-year-old firmware bug in Coldcard wallets allowed remote theft of over 1,300 BTC. The incident exposes critical risks in self-custody, prompting industry debate on security standards and the role of AI in vulnerability discovery.
Woofun AI reports that a dormant firmware vulnerability in Coinkite’s Coldcard hardware wallets triggered a massive Bitcoin heist, exposing critical flaws in self-custody security. The incident, attributed to a coding error from March 2021, allowed attackers to remotely drain funds without physical access or phishing, marking one of the largest digital asset thefts in recent history.
The core of the breach lies in a firmware vulnerability that persisted for five years, originating from a code migration in March 2021 by Block Engineering. During this update, a critical judgment error caused the device to bypass its hardware true random number chip, which is designed to generate unpredictable seeds from physical noise. Instead, the system silently reverted to a software pseudo-random scheme. This fallback mechanism relied on predictable inputs, including chip numbers and timer readings, effectively compromising the cryptographic foundation of the wallet.
The cryptographic impact varied significantly across device models, with the Mk3 model suffering the most severe degradation. For these devices, effective randomness collapsed from the expected 128 bits to approximately 40 bits, rendering them trivially breakable. The Mk4, Mk5, and Q models retained slightly more entropy, around 72 bits, due to additional random values mixed from a security chip.
However, even this reduced strength is far below the threshold required for modern security standards. The vulnerability remained undetected in public firmware until it was massively exploited on July 30, 2026.
Mitigation strategies were limited for affected users, as Coinkite noted that adding at least 50 independent private dice rolls during seed generation or setting a strong passphrase could reduce risk.
However, these measures were not universally applied.Notably, other products in the Coinkite ecosystem, including the Satscard, Opendime, and Tapsigner, were unaffected by this specific vulnerability due to their distinct codebases, highlighting the isolated nature of the firmware flaw within the Coldcard line.
Attack waves unfolded rapidly, with Galaxy Research tracking the initial surge on July 30, where 1,195 addresses were emptied, resulting in the theft of 1,082.65 BTC. The second wave hit on July 31, targeting 1,478 addresses, followed by a third wave on August 1 affecting 1,912 addresses. Crucially, the first wave occurred approximately 30 hours before Coldcard issued an official warning, leaving many users unaware. A suspected fourth wave is currently ongoing, with preliminary estimates indicating an additional 449 BTC stolen, pushing total losses higher.
Woofun AI data shows that market reaction was immediate, with fund flows shifting back toward exchanges after years of migration to self-custody following the FTX collapse in 2022. CryptoQuant research director Julio Moreno reported that on-chain small transfers of less than 1 BTC reached their highest level since November 2022, with approximately 39,600 BTC moved in a single day. This volume was only about 300 BTC lower than the record set shortly after FTX filed for bankruptcy.
Concurrently, Bitcoin’s price weakened, falling from around $65,000 to approximately $63,000 since July 31.
Recovery efforts have been complicated by evolving attack methods. Galaxy Research director Alex Thorn revealed that while most stolen BTC remains in attacker-controlled addresses, some victims have already lost funds. One victim holding nearly 30 Bitcoins had 17 of them exchanged for ETH and deposited into the entertainment platform Duel. Despite the victim emailing the platform to freeze the assets, the funds were transferred out before the freeze could be implemented. Thorn also noted that attackers upgraded their tactics in the third wave, using 293 one-to-one transfer links to avoid consolidation points, making on-chain detection significantly more difficult.
Manufacturer response has been fraught with technical issues. Coinkite described the past three days as one of the most challenging periods in its history, with the team working to contact customers and assist in transferring safe funds. The company destroyed remaining inventory produced with the vulnerable firmware and suspended shipments.
However, users reported that updating the firmware did not fix old seeds, requiring new wallet creation. Compounding the crisis, some users found their Mk4 and Q devices bricked after installing the update, unable to start or stuck on error pages.
The incident has ignited a fierce industry debate on the role of AI and self-custody viability. Binance founder Changpeng Zhao emphasized that developers cannot fix already-generated wallets, leaving security responsibility on users. Bloomberg ETF analyst Eric Balchunas questioned whether users should trust a company with only five employees, suggesting larger institutions offer better security.
Meanwhile, developers claimed to have used Claude Code to scan the open-source firmware, pinpointing the core issue in about eight minutes. Other users reported independent discovery using Zhizhu GLM 5.2. In a bid to restore trust, Bitgo CEO Mike Belshe deposited 100 BTC into a public address, inviting the Claude model from Anthropic to attempt a transfer. Strive Vice President Joe Burnett stated this could be one of the worst weeks in Bitcoin history, advocating for multi-vendor multi-signature solutions for large holdings.
This crisis underscores the fragility of self-custody when reliant on small teams and complex software. While institutional custody offers potential security advantages, it introduces risks of censorship, seizure, and confiscation. The lack of a standard solution leaves users navigating a precarious landscape. As the debate intensifies, the future of self-custody is being re-examined, with many concluding that traditional hardware wallets may no longer suffice for significant Bitcoin holdings.
Comments
No comments yet.