Key Point: A firmware defect in Coldcard hardware wallets disabled secure random number generation across multiple device generations, enabling attackers to drain 594.48 BTC—about $38.3 million.
Coinkite and Block's Bitcoin engineering team traced the root cause to a broken RNG self-check, which left key generation dependent on predictable inputs such as device serial number and internal clock data. For some firmware releases dating back to 2021, affected devices produced little to no true randomness. Early findings also indicate newer models may still reduce the possible entropy to roughly four billion combinations.
Coinkite advises impacted users to create a completely new seed on updated hardware and move funds immediately. The company stressed that firmware updates cannot repair seeds generated with weak randomness.
Based on early analysis, Coinkite said Mk3 users who generated a seed after firmware version 4.0.1 may be exposed. Mk4, Q and Mk5 are not currently believed to be affected.
Why it matters: Weak seed generation can turn self-custody into direct key-exposure risk and may erode confidence in hardware wallet security.
Market Sentiment: Bearish; stress-on; tech-driven; de-risking.
Reason: Confirmation of 594.48 BTC drained from compromised Coldcard seeds adds immediate custody-risk pressure for Bitcoin holders.
Similar Past Cases: In 2023, Trust Wallet patched a browser extension wallet-generation vulnerability tied to roughly $170,000 in user losses. Addresses created during the impacted window required user remediation. (The Block)
Difference: The Trust Wallet incident centered on a browser extension, while this case involves hardware wallet firmware and substantially larger reported Bitcoin losses.
Ripple Effect: The primary spillover is confidence in self-custody. If seed generation depends on predictable data, a wallet that appears secure can be vulnerable by design. If additional firmware versions are confirmed as impacted, the issue could expand from isolated incidents into broader trust concerns around hardware wallets. Exposure may also persist for funds derived from weak seeds.
Opportunities & Risks
Opportunities: Completion of Coinkite and Block's firmware review, especially if it confirms fewer models are affected, could help stabilize sentiment around hardware wallet security. Users who generated a seed on Mk3 after firmware 4.0.1 can reduce key-exposure risk by rotating to a newly generated seed on updated hardware.
Risks: If the review widens the scope of affected firmware, reducing reliance on older seeds becomes critical to limit losses that could surface later. Leaving funds on weak seeds may preserve private-key risk even after firmware is updated.