Coldcard flaw sparks surge in new Bitcoin addresses; Coinkite users report 1,816 BTC stolen
AI Market Summary
A disclosed Coldcard firmware RNG flaw (dating to 2021) enabled offline brute-forcing of mnemonics, with reported losses of at least 1,816 BTC and prompting large-scale wallet migrations that drove new Bitcoin addresses above 330,000. The incident can undermine confidence in self-custody hardware security and temporarily increase on-chain churn as users rotate keys, potentially raising near-term operational and reputational risk across the BTC ecosystem.
Impact level
● Medium
Affected assets
BTC/USDT-0.52%
AI Insight · BTC/USDTAI Insight
▼ Bearish
Trade now
⚠️ AI-generated insights are based on news content and are provided for informational purposes only. They do not constitute investment advice or represent the views of BingX. Investing involves risk. Please trade responsibly.
A Coldcard security issue has prompted a wave of wallet migrations, pushing the number of newly created Bitcoin addresses from about 260,000 to more than 330,000 last week, The Block reported. Since July 30, Coinkite hardware wallet users have lost at least 1,816 BTC—roughly $116 million—across four separate attack waves.
The exposure traces back to a 2021 firmware defect in which mnemonic phrases were generated using a weak software-based random number generator rather than the device's built-in hardware entropy source. That weakness enabled attackers to brute-force wallets generated offline.
Coinkite is urging users who created wallets between March 2021 and the release of the security patch to move funds to newly generated wallets.