The promise that broke
Hardware wallets exist for one reason: to keep your private keys offline, away from anything an attacker can reach. The entire value proposition is distance — your seed phrase never touches the internet, so there is nothing to hack.
Last week, that promise broke at the foundation.
Between July 30 and August 2, an attacker drained over 1,367 Bitcoin — worth nearly $89 million — from more than 4,500 addresses linked to Coldcard hardware wallets. T
The victims’ devices were never connected, never opened, never physically accessed. Some were presumably sitting in safes on another continent.
The victims’ devices were never connected, never opened, never physically accessed. Some were presumably sitting in safes on another continent.
The attacker didn’t need to touch them. They rebuilt the keys from scratch.
What actually happened
Coldcard is a well-known Bitcoin hardware wallet manufactured by Coinkite. When you set up a Coldcard, the device generates a seed phrase — a sequence of 12 or 24 words from which all your Bitcoin addresses and private keys are mathematically derived.
For this to be secure, the seed must be drawn from a source of true randomness. A hardware random number generator (HRNG) built into the chip is supposed to provide that. The number should be so vast and unpredictable that guessing it is computationally impossible.
A firmware build released in March 2021 silently bypassed that generator. An internal configuration setting routed seed generation to a software-based fallback seeded from the chip’s serial number and clock registers.
That’s a problem, because:
- The serial number is fixed factory metadata — public and deterministic.
- Clock values are timing state that an attacker can narrow down or reproduce on their own device.
The result: the space of possible seeds collapsed from astronomically vast — roughly 2²⁵⁶ possibilities — to something on the order of four billion.
Four billion is unimaginable to a person. To a computer, it’s an afternoon’s work.
The attack: pure mathematics, no physical access
Here is the chilling part. The attacker never went near the victims’ wallets.
The process works like this:
- Generate candidate seeds on their own hardware, cycling through the reduced set of possible values.
- Derive the Bitcoin addresses each candidate seed would produce — using the same public derivation rules every wallet follows.
- Check those addresses against the public blockchain — which anyone can download. If an address holds a balance, the corresponding seed is a winner.
- Sweep the funds — sign a transaction with the reconstructed private key and move the Bitcoin out.
Every step runs on the attacker’s own machine. The victim’s Coldcard is irrelevant. It could be powered off in a drawer. The keys were already compromised the moment they were generated.
The attack is still ongoing
Galaxy Research has identified three distinct waves of sweeps, and warned that more are likely:
- Wave 1: 1,196 addresses drained in a 41-minute window on July 30 — 1,082.65 BTC (~$70M).
- Wave 2: Additional sweeps expanding the total.
- Wave 3: 1,912 addresses hit between Friday and Saturday, using a different collection pattern — sending each victim’s coins to a unique destination address rather than a shared collector, and using pay-to-witness-script-hash outputs that can carry multisig or timelock conditions.
As of August 2, total observed losses stand at 1,367 BTC (~$89M) across 4,585 addresses.
The attacker is now targeting smaller balances and changing tactics to evade tracking. This is not over.
You can’t check if you’re affected
Perhaps the most unsettling detail: there is no test you can run on your Coldcard to determine whether your seed was generated on the vulnerable firmware.
Coinkite has warned Mk3 owners and claims newer devices are unaffected, but researchers at Block have placed the Mk2, Mk4, Q, and Mk5 in scope as well. Until that dispute is resolved, anyone who generated a seed on a Coldcard during the affected period has to assume the worst.
The only safe action is to generate a fresh seed on a verified, unaffected device and move your funds.
Why this matters beyond Coldcard
This exploit is significant not because of the dollar amount — larger thefts have occurred — but because of the mechanism. It invalidates the core assumption of self-custody: that an offline key is a safe key.
The attack surface wasn’t a phishing email, a malicious dApp, or a compromised exchange. It was the randomness itself — the foundational layer that every wallet, every exchange, every custody solution depends on. If the randomness is weak, the entire key is weak. No amount of operational discipline on the owner’s part can fix that.
This raises uncomfortable questions for anyone managing their own Bitcoin:
- How do you verify that your hardware wallet’s RNG is actually working?
- How do you know your seed wasn’t generated on vulnerable firmware years ago?
- What happens when the next device is found to have a similar flaw?
What Bitkaya does differently
This is exactly the scenario that institutional custody is designed to prevent.
At Bitkaya, we don’t rely on a single hardware wallet generating a single seed behind a single chip. Our Crypto Custody service for businesses uses institutional-grade wallet infrastructure with multiple layers of protection:
- Multi-signature architecture — no single key can authorize a transaction, so a single weak seed doesn’t expose funds.
- Professional key management — keys are generated, stored, and operated under documented procedures with hardware security modules (HSMs), not consumer-grade chips with unaudited firmware.
- Approval flows — transactions require authorization through defined governance processes before they execute.
Also read our press release: /blog/bitkaya-press-releases-2/bitkaya-confirms-no-exposure-to-89m-coldcard-wallet-exploit-9
What you should do right now
If you use a Coldcard wallet:
- Assume your seed is compromised if you generated it on a device that may have been running affected firmware (Mk2, Mk3, Mk4, Q, or Mk5).
- Generate a new seed on a verified, unaffected device — ideally a different manufacturer entirely.
- Move your Bitcoin to the new addresses immediately.
- Do not reuse any address associated with the old seed.
If you manage crypto for a business or organisation:
- Audit your key generation process — when were keys generated, on what hardware, with what firmware version?
- Consider multi-signature setups — don’t rely on a single key, a single device, or a single seed.
- Evaluate professional custody — if a single firmware flaw can drain your treasury, your custody model has a single point of failure.
The bottom line
The Coldcard exploit is a wake-up call, not just for Coldcard owners but for anyone who believes that buying a hardware wallet is the end of their security journey.
Self-custody is powerful, but it places the full burden of key management on the individual. When the randomness fails, everything above it fails — silently, and without recourse.
Institutional custody exists precisely because most organisations cannot — and should not — carry that burden alone. The question isn’t whether you can secure your own keys. It’s whether you can verify that every layer beneath them is sound.
If this exploit has prompted questions about how your organisation manages digital asset security, talk to Bitkaya. We help businesses in Curaçao and beyond set up custody, execution, and treasury monitoring with the governance standards your board — and your auditors — expect.