Coldcard Seed-Generation Flaw Tied to Over $88 Million in Bitcoin Losses

AI Market Summary
Reports of a Coldcard seed-generation randomness vulnerability linked to theft of ~1,367 BTC (over $88m) elevate counterparty and operational risk perceptions around self-custody hardware security. The incident may increase near-term caution toward hardware wallets and renew scrutiny of vendor security practices and data retention policies, potentially weighing on broader crypto risk sentiment even if the direct impact is concentrated in affected users' funds.
Impact level
● Medium
Affected assets
BTC/USDT+1.33%
AI Insight · BTC/USDTAI Insight
▼ Bearish
Trade now
⚠️ AI-generated insights are based on news content and are provided for informational purposes only. They do not constitute investment advice or represent the views of BingX. Investing involves risk. Please trade responsibly.
Odaily Planet Daily reports that a weakness affecting the randomness used to generate seed phrases on Coldcard hardware wallets made by Coinkite has been exploited, with threat actors stealing more than 1,000 BTC over the past two days. Galaxy Research data shows that as of 5:36 p.m. ET on Saturday, 1,367 BTC was involved in the incident, implying losses of more than $88 million. Coinkite said it has issued security warnings to potentially impacted users, sending alerts to email addresses collected through its store and newsletter systems since 2019. Coldcard confirmed the emails did come from Coinkite and said the company reached out to all addresses it could access. The outreach has also renewed criticism of Coinkite's retention of customer email data. The company said its public policy allows it to keep purchase-related email addresses so customers can log in and view other information, adding that this data has since been cleared. It did not provide a deletion timeline, saying the addresses would be retained "temporarily." Coinkite cofounder and CEO Rodolfo Novak has previously said the company does not store customer information and deletes customer data 90 days after purchase, while also offering an option to buy anonymously.