Coldcard Hardware Wallet Vulnerability Linked to $88 Million Bitcoin Theft
AI Market Summary
A disclosed Coldcard hardware wallet key-generation flaw reportedly enabled attackers to steal over $88M in BTC, with the exploit described as ongoing and funds aggregating on-chain. While not a protocol-level Bitcoin issue, the incident can pressure near-term sentiment by elevating custody and operational risk, potentially prompting accelerated self-custody migrations, heightened scrutiny of hardware wallet supply chains, and increased monitoring of related addresses by exchanges and compliance teams.
Impact level
● High
Affected assets
BTC/USDT+0.79%
AI Insight · BTC/USDTAI Insight
▼ Bearish
Trade now
⚠️ AI-generated insights are based on news content and are provided for informational purposes only. They do not constitute investment advice or represent the views of BingX. Investing involves risk. Please trade responsibly.
On July 31, a security flaw in Coldcard hardware wallets led to the compromise of approximately 500 devices and the theft of 594 BTC, then valued at $38 million. According to blockchain security firm Beosin, total losses linked to this vulnerability have now surpassed $88 million as the exploitation campaign remains active. Coinkite, the manufacturer, confirmed the flaw impacts multiple generations, including Coldcard Mk2, Mk3, Mk4, Q, and Mk5. Technical analysis reveals that a firmware configuration error disabled the default hardware random number generator, causing the system to fall back to a predictable pseudorandom generator. Beosin Trace has identified several aggregation addresses holding the stolen funds, including one containing 562 BTC. Users are urgently advised by both Beosin and Coinkite to migrate assets to new addresses immediately to prevent further losses.