After Coldcard Was Hacked, $15 Billion in Bitcoin Moved to Safety
A major Coldcard hardware-wallet exploit exposed a firmware bug in versions 4.0.1–4.1.9 that routed key generation through weak software randomness instead of the device’s hardware entropy source. That reduced private-key security from about 128 bits to roughly 40, making affected seeds effectively guessable. The breach, discovered after July 30, has already drained close to $130 million in Bitcoin, with analytics firms estimating losses around 1,596 BTC across more than 5,200 addresses. The incident also triggered a large defensive shift onchain. Roughly 233,000 BTC moved out of long-term holder wallets as users migrated funds to new storage, including multisig setups and other hardware wallets. That response far exceeded the stolen amount and is being cited as evidence that self-custody can improve Bitcoin’s resilience: attackers had to break wallets individually, while the broader network had time to react. Coinkite advised anyone who created a seed on the affected firmware to treat it as compromised and move funds immediately.
