Coldcard Hack Losses Near $100M as Bug's Wider Impact Revealed
A vulnerability in Coldcard hardware wallets has resulted in losses of nearly $100 million. According to Galaxy Research, the confirmed theft amounts to 1,596 BTC ($63,871.00 · Live) stolen from roughly 7,300 addresses across three confirmed waves and a potential fourth wave.
The bug was traced back to a firmware macro flaw introduced in March 2021, which silently redirected seed generation away from the device's hardware random-number generator. The affected models include Mk2/Mk3, Mk4/Mk5, and Q devices, although only the older models have been targeted so far.
The first wave occurred on July 30, with Galaxy Research identifying 1,196 addresses and 1,082.65 BTC ($70.2 million) swept in a 41-minute window. The second wave, identified on August 1, brought the total to 1,158.66 BTC across 2,673 addresses.
The third wave was spotted on August 2, with Galaxy Research confirming that this wave's transaction pattern did not share a fingerprint with the first two waves and should not be assumed to be the work of the same operator. A fourth wave is suspected, but has yet to be confirmed by any victims.