Coinkite's Coldcard Wallet Bug Drains More Than $83 Million in Bitcoin as New Waves of Theft Emerge

A firmware flaw in Coinkite's Coldcard hardware wallet has turned into one of the largest self-custody losses in Bitcoin's history, with an attacker draining funds from hundreds of wallets that generated seeds on affected devices going back to March 2021.
WHAT HAPPENED
The first confirmed sweep hit in the early hours of July 30, when an attacker moved bitcoin out of roughly 500 wallets in a matter of minutes. AnchorWatch CEO Rob Hamilton tracked a total of 1,324 spent outputs in 500 transactions which took place across three blocks, with 562 BTC later consolidated into a single address. The theft did not stop there. Within days the exploit had already drained more than 1,300 bitcoin, worth roughly $83 million, from thousands of addresses across multiple waves, making it one of the biggest self-custody failures in Bitcoin history.
THE ENTROPY FLAW
The root cause traces back to how Coldcard devices generated the random seed words that protect a wallet. Coinkite says Mk3 seeds had about 40 bits of entropy instead of 128. Later models were not immune either, since only a limited portion of the intended randomness reached the seed generator on newer hardware. Coinkite CEO Rodolfo Novak, known in the community as NVK, took the blame publicly and did not soften the news.
"I'm sorry and I'm devastated. Our team is heartbroken about yesterday's news," Novak wrote.
WHO IS AT RISK
Coinkite's own guidance draws a clear line around who needs to act. The company said customers who created their recovery phrase using at least 50 private dice rolls are not affected by this specific flaw alone. Everyone else who generated a seed natively on an affected device, without added entropy or a strong passphrase, should treat their funds as exposed. Installing new firmware is not enough on its own. "Updating the firmware does not repair a seed that was generated by affected firmware," the company said.
WHAT TO DO NOW
Anyone still holding funds on an affected Coldcard should generate a fresh seed on a device confirmed to be unaffected and move funds off the old wallet rather than reuse it. Coinkite has continued patching firmware across its device lineup as investigators keep tracing new batches of stolen coins, and researchers have cautioned that any address whose public key was ever exposed on a vulnerable device remains a target until the funds are moved.
This story comes from the Simply Bitcoin Live show. Watch the full episode.


