A Coldcard firmware flaw let hackers drain $70M in Bitcoin in just 41 minutes. Here's what happened and what you should do to protect your crypto.
On July 30, an attacker pulled off one of the most audacious heists in crypto history. In just 41 minutes, they drained 1,196 Bitcoin addresses, walking away with 1,082.65 BTC โ roughly $70.2 million at the time. That's not a typo. Forty-one minutes.
Galaxy Research mapped out the entire sweep, and what they found is both fascinating and terrifying: the root cause traces back to a firmware flaw in Coldcard, the Bitcoin-only hardware wallet made by Canadian company Coinkite.
### The March 2021 Mistake That Started It All
Here's where it gets interesting. Back in March 2021, a firmware integration error quietly slipped into Coldcard's codebase. That error routed seed generation through a deterministic software pseudorandom number generator (PRNG) instead of the hardware's secure random number generator.
For those of us who aren't cryptography nerds, let me break that down. When you set up a hardware wallet, it creates a seed phrase โ those 12 or 24 words that give you access to your funds. That seed needs to be generated using true randomness from the hardware's secure element. But this bug meant the seed was being created using software-based randomness, which is predictable.
And predictable is the enemy of secure.
### Why This Flaw Was So Dangerous
Think of it like this: if you lock your front door with a key that's a copy of every other key in your neighborhood, then anyone who figures out the pattern can walk right in. That's essentially what happened here.
The PRNG flaw meant that seeds weren't truly random. An attacker who understood the flaw could potentially reproduce the seed generation process and derive the private keys for affected wallets. It's a nightmare scenario for anyone who trusts their hardware wallet to keep their Bitcoin safe.
Galaxy Research's analysis shows the attacker didn't just stumble onto this. They systematically swept through addresses, likely using the knowledge of the PRNG flaw to calculate which wallets were vulnerable. The speed โ 1,196 addresses in under an hour โ tells you this was automated and deliberate.
### What This Means for Coldcard Users
If you're a Coldcard user, you're probably feeling a little uneasy right now. That's understandable. Here's what you need to know:
- The flaw is tied to a specific firmware integration error from March 2021
- Not every Coldcard wallet is necessarily affected โ it depends on when and how your seed was generated
- Coinkite has likely addressed this in subsequent firmware updates, but you should verify your setup
If you bought a Coldcard and generated your seed around that time frame, it might be worth considering a fresh wallet setup. Generate a new seed, move your funds, and make sure you're running the latest firmware.
### The Bigger Picture on Hardware Wallets
This incident is a stark reminder that hardware wallets aren't bulletproof. They're incredibly secure compared to hot wallets, but they're still software and hardware built by humans. Bugs happen.
What separates a good hardware wallet from a great one is how the company responds to flaws. Coinkite has a solid reputation in the Bitcoin community, and their response to this will be telling. But for now, the lesson is clear: don't blindly trust any device. Stay updated, stay informed, and always double-check your security practices.
### Your Next Steps
If you're holding Bitcoin on a Coldcard, don't panic โ but do take action. Check your firmware version, review how your seed was generated, and consider a fresh setup if you have any doubts. The $70 million theft is a wake-up call for everyone in the crypto space.
Hardware wallets are still the gold standard for self-custody. But this incident proves that even the best tools can have hidden flaws. Stay vigilant, keep your firmware updated, and never assume you're untouchable.
In the end, security isn't a product you buy โ it's a practice you maintain.