Coldcard Firmware Flaw Drains Over $70 Million in Bitcoin, Coinkite CEO Apologizes

Coinkite's Coldcard, long treated as the flagship hardware wallet for Bitcoin self-custody, is at the center of one of the largest security failures the community has faced. A firmware flaw let attackers predict the seed phrases behind thousands of wallets, and by the end of the week the losses had grown well beyond initial estimates.
WHAT WENT WRONG
Block's hardware lead, Max Guise, said the company's engineering and security teams began looking into reports of non-Bitkey wallets being drained and traced the problem to Coldcard rather than any Block product. First, no Block products including Bitkey were affected.
Block discovered two vulnerabilities affecting non-Block products, including Coldcard Mk2, Mk3, Mk4, Q, and Mk5, at varying levels of severity. On the Mk2 and Mk3, the firmware was meant to use the hardware random number generator to create keys, but a mistake in a macro defined in the firmware led to using only a known device ID, timer state, and call history, making wallet generation deterministic instead of random. The Mk4, Q, and Mk5 attempted to compensate at boot with secure element input, but the reseed process truncated that input to just 32 bits, sharply limiting the entropy it contributed.
Exporting a seed generated on a vulnerable Coldcard and moving it to another wallet does not fix the problem, since the same insecure seed remains at risk wherever it goes.
HOW MUCH BITCOIN IS GONE
The first estimates put the losses at 594 BTC, worth about $38 million, drained from roughly 500 wallets inside 25 minutes. By the following day, Galaxy Research said nearly 1,200 addresses had been drained of more than 1,000 BTC, worth roughly $70 million, tied to the vulnerability. Galaxy Research warned that future attacks remain possible on any Coldcard-generated address and do not need to match the pattern seen so far.
COINKITE'S RESPONSE
Coinkite CEO Rodolfo Novak, known as NVK, posted an open letter to the community. "I'm sorry and I'm devastated," he wrote. "Our team is heartbroken about yesterday's news." He told anyone who had generated a seed using a Coldcard wallet to move their funds immediately, using the company's updated best practices. Coinkite shipped a hotfix that protects newly generated seeds, but the fix does not repair a seed already created on vulnerable firmware.
Novak said the company "took full accountability for the firmware bug that led to this situation," acknowledging that its own review process had failed to catch the flaw. He also pointed to artificial intelligence as a factor in how the bug was found. "We believe this is a sober reality of the new AI paradigm," he wrote. "AI-assisted code review can now find latent bugs at a speed that is outpacing even the industry's most seasoned experts."
"This is the worst hit in bitcoin history to the most knowledgeable and 'properly secured' bitcoiners," said Bitcoin commentator Guy Swann.
WHAT AFFECTED USERS SHOULD DO
On the show, the hosts said anyone running a Coldcard MK2 through MK5 or Q who generated their seed using the device's built-in random number generator, rather than manually rolling dice for their own entropy, should treat that seed as compromised and move funds to a different device or a trusted exchange without delay. Updating firmware protects a future seed, not one already generated on the flawed code.
WHY IT MATTERS
The breach does not touch Bitcoin's protocol or its cryptography. It exposes how much of the self-custody movement still rested on one hardware vendor generating a random number correctly, and how fast that trust unravels when it doesn't. Coldcard's own reputation, built over roughly a decade as the choice for security-minded Bitcoiners, is now the story's biggest casualty.
This story comes from the Simply Bitcoin Live show. Watch the full episode.


