Coldcard Exploit Drains $118M as Bitcoin Flows Back to Exchanges
The Coldcard exploit has drained an estimated $118 million from hardware wallets since July 30. The issue stems from a firmware build error that reduced seed entropy to approximately 40 bits on Mk3 devices and 72 bits on Mk4/Mk5/Q models, making private keys guessable through brute force.
Four coordinated attack waves have swept approximately 1,816 BTC across 5,294 addresses. The exploit is not a hack in the classical sense, but rather an error that allowed attackers to guess weak private keys.
The Coldcard crisis has reversed the trend of users moving bitcoin from exchanges to self-custody wallets, instead driving it back to regulated exchanges and institutional custodians.