Coldcard firmware flaw enabled $116 million Bitcoin heist since July 30
A firmware vulnerability in Coldcard devices dating to March 2021 has enabled attackers to steal approximately $116 million in Bitcoin from over 5,200 addresses. The flaw caused the devices to bypass their hardware randomness chip during key generation, using predictable software substitutes instead, making wallet seed phrases enumerable. The incident has been called the worst self-custody loss in Bitcoin history.
The vulnerability, embedded in the firmware since March 2021, allowed attackers to exploit a critical flaw in the key generation process. Instead of relying on the device's dedicated hardware randomness chip, the firmware fell back to predictable software-based randomness, making the resulting seed phrases mathematically vulnerable to enumeration.
This security lapse enabled the theft of roughly $116 million in Bitcoin across more than 5,200 distinct wallet addresses. The scale of the loss has led observers to characterize this event as the most severe single incident affecting self-custodied digital assets in the cryptocurrency's history.
This incident could significantly undermine user confidence in hardware wallets, which are often marketed as the most secure method for self-custody. Affected individuals may face irreversible financial loss, while the broader crypto community may reconsider the reliability of firmware updates and hardware randomness guarantees. The event may also prompt stricter regulatory scrutiny or industry-wide audits, though the decentralized nature of Bitcoin means recovery options remain limited for victims.