Bitcoin (BTC) Coldcard Exploit Losses Top $100 Million
Coldcard firmware flaw drove more than $100 million in Bitcoin losses. COINOTAG tracks BTC support, resistance, funding and sentiment.
AI SummaryAI
- Coldcard's firmware flaw reduced older Mk2 and Mk3 Bitcoin seed entropy to about 40 bits from the intended 128 bits.
- On-chain analysis counted 1,596 BTC taken across three confirmed waves and 14 smaller incidents, with a suspected fourth wave raising the estimate to 2,055 BTC.
- At least 15 distinct attackers are sweeping vulnerable Coldcard wallets, including one newly identified actor who withdrew 12 BTC from 126 addresses.
- Coldcard advised users to move Bitcoin to freshly generated wallets and said a temporary true-random-number-generator error can be cleared by power cycling.
Bitcoin (BTC) holders using Coldcard hardware wallets have lost more than $100 million after a firmware flaw made private-key generation predictable. The episode is a stress test for Bitcoin self-custody. The problem stemmed from a 2021 code migration that silently redirected seed creation away from the device's hardware random number generator to a software fallback intended for machines without such a chip. Because a build flag treated a zero value as defined, the fallback remained active, reducing entropy on older Mk2 and Mk3 models to about 40 bits from the intended 128. On-chain analysis counted 1,596 BTC taken across three confirmed waves and 14 smaller incidents, with a suspected fourth wave lifting the estimate to 2,055 BTC, or roughly $130 million.
At least 15 distinct attackers are now sweeping vulnerable Coldcard wallets, and the count is still rising. One overnight case began when an owner reported losing less than one BTC; blockchain analysis then uncovered a previously uncatalogued actor who had already withdrawn 12 BTC from 126 addresses. Researchers have labeled each cluster alphabetically, with the newest footprint designated O. Because the flaw is public, any technically capable party can scan the Bitcoin ledger for weak keys and brute-force them. Coinkite has acknowledged the bug, shipped fixes for affected firmware tracks, and warned that the threat remains active. It also stressed that updating firmware does not repair an already-generated seed.
Coldcard's latest advisory tells users to treat the exploit as unresolved and to move funds into freshly generated wallets. The company said assets should be transferred to newly created recovery phrases, firmware should be updated, and addresses derived from old paths should no longer be used. It also rejected claims that the current fix permanently disables devices, saying a temporary true-random-number-generator error should be cleared by cutting power and restarting. According to the statement, such an error does not write data to flash memory, and the system is designed to shut down safely. Developers are preparing an additional patch with limited retries, seed-error detection, and erasure of prior RNG output, while Mk3 support will arrive separately.
The security crisis has also coincided with rare movement from a long-dormant Bitcoin address. Blockchain records show a legacy wallet holding 500 BTC, worth about $32 million, transferred its entire balance after 12 years of inactivity and paid only 191 satoshis, roughly $0.12, in fees. Some observers linked the timing to the Coldcard incident, although on-chain data alone cannot prove whether the owner was reacting to the exploit or simply reorganizing custody. Long-inactive coins often raise speculation about lost keys or whale sales, but such transfers can also reflect routine consolidation into newer storage. The episode underscores how quickly self-custody assumptions can change during an active vulnerability.
One wallet believed to hold about $36 million in stolen BTC has become an improvised message board. Since the theft, the address has received 23 small deposits, 14 of them carrying written notes via OP_RETURN or similar metadata. Senders have transferred about 81,527 satoshis, worth roughly $52 after fees, while paying around 9,706 satoshis in network costs. The messages range from requests for partial refunds and bargaining notes to haikus, aphorisms, offers to launder the funds, and scam advertisements. One entry even tried to instruct the wallet to empty itself, treating the thief as if it were an AI Crypto Wallet rather than a human attacker.
The confirmed loss tally has escalated quickly, giving investigators a moving target. Within five days, the estimate rose from $38 million when the first sweep appeared, to $88.6 million by Saturday, and then beyond $100 million. The confirmed scope covers 1,596 BTC from roughly 7,300 addresses across three major waves and 14 smaller incidents; a suspected fourth wave would extend the total to 2,055 BTC, close to $130 million. Seventy-three victims have contacted researchers, helping identify opportunistic footprints. About 90% of the stolen BTC remains unmoved, and address data has been shared with U.S. federal law enforcement, exchanges, and cyber-investigation firms. Fixed firmware shipped on July 31, but it cannot restore compromised seeds.
(as of 03:04 UTC) COINOTAG's proprietary 42-indicator composite S/R scoring engine shows Bitcoin (BTC) at $64,395.55 as of the latest data, up 0.92%, with price sideways and MACD bearish. The $63,967 support scores 70/100, backed by EMA 20, Pivot Point, HVN, and Ichimoku Tenkan; resistance at $65,611 scores 53/100 from flip S→R and Swing High, while $66,722 rates 76/100 on LVN, Fibo 0.382, and EMA 100. Funding is 0.0033%, open interest $13.11 billion, and the long/short ratio 1.28, showing modest long bias. Fear & Greed at 27 reads Fear. Reclaiming $65,611 targets $66,722; losing $63,967 invalidates the neutral base and opens $62,840. Bitcoin's 69.7% tracked share favors defensiveness over the altcoin field, though Fear alone does not confirm a bear-market.
Related Tags

AI-generated, AI-reviewed, under COINOTAG editorial oversight.


