Bitcoin (BTC) Coldcard Hack Losses Confirmed at $111 Million
BTC/USDT
$7,742,896,984.36
$65,390.99 / $64,525.00
Change: $865.99 (1.34%)
+0.0015%
Longs pay
AI SummaryAI
- The Coldcard hack produced $111 million in confirmed Bitcoin losses, with investigators warning the final figure could be higher.
- The typical stolen Bitcoin had not moved for 3.5 years, and 88% of affected funds were dormant for at least one year.
- For individual victims, the median loss reached 1.022 BTC, with an average of 4.04 BTC.
- Coinkite linked the theft to Mk3 firmware version 4.0.1 introduced in March 2021.
Bitcoin News
Bitcoin (BTC) holders using Coldcard hardware wallets suffered a coordinated theft that has produced $111 million in confirmed losses, with investigators warning the final figure could be higher. An analysis of 250 victim reports reviewed by analysts found that the stolen coins were overwhelmingly old, long-idle holdings. The typical coin had not moved for 3.5 years before it was drained, and 88% of the affected funds had been dormant for at least one year. The distribution of losses was uneven. By address, median losses stood at 0.014 BTC, while mean losses reached 0.212 BTC. For individual victims, the median loss reached 1.022 BTC, with an average of 4.04 BTC. One account was hit for 58.97 BTC, according to the victim-report sample. The first wave began last Thursday with more than $35 million taken, and the draining continued through the weekend as security researchers urged users to move funds. Coinkite, the Toronto-based maker of Coldcard, said the problem stemmed from firmware introduced with version 4.0.1 in March 2021 on Mk3 devices. In those builds, seed creation could default to a software-based pseudorandom routine, bypassing the device's hardware true-random source and leaving recovery phrases more exposed to prediction. Coinkite acknowledged that the defect had gone undetected across multiple releases, expanding its potential impact over time. The incident became a multi-day containment effort, with community members and the wallet maker repeatedly urging users to transfer funds before additional vulnerable addresses were emptied. The urgency reflected the exploit's unusual nature: attackers did not need physical access to devices, only the ability to reconstruct weak seeds generated years earlier. As the scale became clear, users began shifting coins to alternative storage, including exchanges, while Coinkite told affected owners to update software or move assets away from vulnerable seeds. For Bitcoin custody, the episode highlights how firmware-level entropy failures can undermine even offline storage.
A wallet linked to the Coldcard theft broke its silence on Aug. 7, moving 30.185 BTC, then valued near $1.94 million, into a fresh address. The transfer followed weeks of wallet inactivity and immediately raised questions about whether more dormant attacker balances will be activated. On-chain tracking shows the transfer was the first movement from the attacker-controlled wallet since the initial drain, making it a focal point for investigators monitoring whether the stolen funds will eventually be cashed out. The amount represented roughly 1.5% of the estimated 2,055 BTC tied to the exploit. Earlier on-chain analysis identified three confirmed waves that removed 1,596 BTC from about 7,300 addresses, while a possible fourth wave lifted the likely total to around 2,055 BTC, near $130 million. Before this transaction, about 90% of the stolen coins had stayed in their original destination wallets, leaving the new transfer as the clearest signal yet that the attacker may be preparing to move value. The transaction does not prove an imminent sale. In theft cases, actors often shift assets through layered wallets before attempting to exchange them for other tokens or fiat currency. Because every Bitcoin transfer is recorded on a public ledger, identified attacker addresses can be followed as funds move. The same transparency allows exchanges and investigators to flag tainted coins. Coinkite's post-incident guidance remains central to limiting further damage. The company's guidance told owners of vulnerable seeds to relocate assets, generate replacement seed phrases, and install the corrected firmware. It also warned that any seed phrase produced on an affected device should be treated as compromised, even if funds have not yet moved. The response effort has so far included sharing attacker and victim address data with U.S. law enforcement, cryptocurrency exchanges, and cyber-investigation teams, while work still continues to identify additional attacker wallets.
COINOTAG's analysis ties both developments to one theme: the Coldcard breach was not a market event but a key-generation failure, and the public ledger now provides the audit trail. Coinkite's post-mortem identifies the root cause as Mk3 firmware falling back to a weak pseudorandom generator. On-chain records and the confirmed tally show $111 million in losses, alongside the first 30.185 BTC transfer. Remediation is explicit: update firmware, generate new seeds, and migrate funds. Whether the attacker exits through an altcoin, fiat, or an exchange, the response is the same: treat vulnerable seeds as compromised, regardless of whether coins were bought near an all-time high or accumulated through a bear market.
Add COINOTAG as a Preferred Source
Add COINOTAG to your preferred sources in Google News and Search to see our coverage first.
Add on GoogleRelated Tags
AI-generated, AI-reviewed, under COINOTAG editorial oversight.


