Skip to content
Back to Guavy Wire
Crypto

Coldcard Vulnerability Exposed: 1800+ BTC Stolen via Mnemonic Weakness

Instruments
BTC
Share

A vulnerability in Coldcard hardware wallets has led to at least 1,815.75 BTC being stolen from approximately 5,294 addresses since 2021.

The issue arose due to a code migration error in 2021, where some devices mistakenly connected the wallet seed generation path to a software pseudo-random number generator instead of the intended hardware random number generator.

This resulted in a significantly lower actual search space for mnemonics generated by some firmware compared to the design target, making it easier for attackers to exploit.

Galaxy Research identified four rounds of suspected attacks involving 1,367.05 BTC and 4,585 addresses, with a fourth round detected on August 3.

Coinkite, the manufacturer of Coldcard, initially denied any device-level vulnerability but later expanded the affected scope to include Mk2, Mk3, Mk4, Mk5, Q, and Q Edge devices using specific firmware versions.

More on Crypto

Disclaimer: Guavy is a data and market intelligence provider, not an investment advisor. The information, signals, and market analysis provided by the Guavy API and related services are for informational purposes only and are not intended as financial advice, investment recommendations, or an endorsement of any particular trading strategy. Trading in volatile markets, including cryptocurrency, carries significant risk and may not be suitable for all investors. Past performance is not indicative of future results. Users should consult with a qualified financial professional before making any investment decisions. Guavy makes no guarantee of trading profits or financial returns.

Market sentiment intelligence for apps, funds & agents

Location

729 55 Ave SW
Calgary AB T2V 0G4
Canada

© 2026 Guavy Inc