Skip to content
Back to Guavy Wire
Crypto

Coldcard Firmware Flaw Exposes Thousands of Wallets to Remote Attack

Instruments
BTC
Share

A vulnerability in the March 2021 Coldcard firmware release allowed attackers to drain Bitcoin from thousands of wallets without needing physical access.

The flaw, which Coinkite estimates affects around 40 bits of entropy on the Mk3 and about 72 bits on the Mk4, Mk5, and Q models, enables remote key derivation by bypassing the hardware random number generator.

Galaxy Research identified 1,196 addresses involved in transactions tied to the July 30 sweep, tracing activity between 1:10 AM and 1:51 AM UTC across blocks 960,183 to 960,191. The attackers used a deterministic software pseudorandom number generator instead of the STM32 hardware random number generator, allowing them to reproduce candidate output streams offline.

The losses from this attack are estimated near $89 million, with the latest wave targeting smaller balances and using more complex transaction patterns. Galaxy Research warned that future attacks may not reuse the same on-chain 'fingerprint,' meaning wallet owners should be cautious and consider migrating their funds.

More on Crypto

Disclaimer: Guavy is a data and market intelligence provider, not an investment advisor. The information, signals, and market analysis provided by the Guavy API and related services are for informational purposes only and are not intended as financial advice, investment recommendations, or an endorsement of any particular trading strategy. Trading in volatile markets, including cryptocurrency, carries significant risk and may not be suitable for all investors. Past performance is not indicative of future results. Users should consult with a qualified financial professional before making any investment decisions. Guavy makes no guarantee of trading profits or financial returns.

Real-time market sentiment intelligence for apps, funds & agents

Location

729 55 Ave SW
Calgary AB T2V 0G4
Canada

© 2026 Guavy Inc