Markets
BTC
ETH
SOL
XRP
BNB
ADA
DOGE
MCap
BTC
ETH
SOL
XRP
BNB
ADA
DOGE
MCap
Tech

594 Bitcoin Left 500 Coldcard Wallets in a 25-Minute Sweep

A 2021 firmware bug quietly gutted seed entropy on Mk3 devices, and an attacker who noticed swept the lot before dawn. Coinkite says Mk4, Q and Mk5 look safe on early analysis.

By William Dale··3 min read
594 Bitcoin Left 500 Coldcard Wallets in a 25-Minute Sweep

Key Points

  • A 2021 firmware bug quietly gutted seed entropy on Mk3 devices, and an attacker who noticed swept the lot before dawn.
  • Coinkite says Mk4, Q and Mk5 look safe on early analysis.

Between 01:31 and 01:56 UTC on Friday, an attacker moved 594 bitcoin out of roughly 500 single-signature Coldcard wallets in 500 transactions across a three-block window. The take was worth about $38 million at prevailing prices. Every drained wallet held more than 0.15 BTC, most had sat dormant for years, and their creation dates lined up almost exactly with a firmware bug shipped by Coinkite in March 2021.

The mechanics are ugly. A seed phrase, the twelve or twenty-four words that control a bitcoin wallet, is meant to be sampled at random from a space so large that guessing it is arithmetically impossible. Coldcard's Mk3 firmware version 4.0.0 broke that assumption. Block's bitcoin engineering team, which published the disassembly, found that a build flag told the device to skip its hardware random number generator, and a safety check in the supporting library only tested whether the flag existed rather than whether it was on. Key generation fell through to a basic software substitute seeded from the chip's serial number and a handful of clock registers.

None of those are secrets. Serial numbers are factory metadata. Clock values can be narrowed to a small window by anyone with an identical Mk3 on their bench. What was supposed to be 128 bits of entropy behind every 12-word mnemonic collapsed to something an attacker with enough patience and enough Mk3 hardware could enumerate. On Friday morning, someone did.

Advertisement

728×90

Coinkite has warned owners that any seed generated on an Mk3 running firmware 4.0.1 or later should be considered compromised. Its Mk4, Q and Mk5 devices are unaffected on early analysis. The company urged affected users to move funds to a fresh wallet immediately, but the guidance arrived after the sweep. The 562 BTC the attacker consolidated into a single address, worth roughly $35.9 million, has not moved.

Exposure runs past the wallet seed itself. The same broken generator produced Coldcard's paper wallet private keys, seed-splitting masks, device cloning keys and Key Teleport transfers. Anyone who used a compromised Mk3 for any of those functions is holding assets a stranger can spend. Block said it disclosed the flaw to Coinkite but chose to publish before completing its testing because exploitation was already in progress.

The Coldcard case is the second self-custody failure in eight weeks tied to how a single device or process handled secrets. Humanity Protocol lost $36 million in June because an engineer backed up multisig keys to a personal laptop that later got compromised. That was a human error. The Coldcard drain is closer to a factory defect, and the factory shipped it five years ago.

A wallet compromised in March 2021 has had five years of price movement running against its owner. Users who left bitcoin on an Mk3 they thought was air-gapped watched it appreciate on-chain while an entropy leak sat inside the device waiting to be found. Every day the flaw stayed hidden was a day the loss grew.

Bitcoin barely reacted. The token traded above $64,000 through Asian hours on Friday. A $38 million theft is real money to the people who lost it and a rounding error against the market's daily volume. The Bitfinex hack of 2016, the Mt. Gox collapse of 2014, the Ronin bridge drain of 2022; the price line barely bends around any of them.

What the Coldcard episode ends is a specific piece of marketing. Hardware wallets are sold as the answer to trust, the device you can hand to a relative and know that no phishing site, no exchange collapse and no compromised laptop can reach the coins. That story assumes the box does what it says on the packaging. When the box has been generating predictable seeds since 2021 and nobody caught it until an attacker did, the argument for hardware becomes a different one: it is safer than the alternative, not safe by itself. Vitalik Buterin argued in May that AI-assisted formal verification would be the only durable defence against exactly this class of bug. The Coldcard flaw is the case for him.

Coinkite's post is careful and short. The Block write-up runs longer. Neither answers the question a Mk3 owner is going to ask first, which is whether their specific seed sits in the compromised set. Until Coinkite says otherwise, if it was generated on the affected firmware, it should be treated as spent.

MiningPool content is intended for information and educational purposes only and does not constitute financial, investment, or legal advice.

Advertisement

728×90

Related Stories

Stay informed

Verifiable crypto journalism, delivered to your inbox.

Weekday mornings. No hype. No financial advice. Just what happened and why it matters.

No spam. Unsubscribe anytime. Read our privacy policy.