🔥BTC/USDT

Coldcard exploit exposes predictable Bitcoin private keys

A flaw in seed generation on certain Coldcard Bitcoin hardware wallets allowed attackers to reconstruct private keys and steal funds, turning a device designed to keep credentials offline into a target for remote exploitation. Galaxy Research estimates that at least $111 million has been confirmed stolen, with total losses likely to exceed $130 million as analysis of affected wallets continues.

The incident centers on the randomness used to create a wallet seed, the master secret that generates the private keys controlling Bitcoin. Ido Ben-Natan, chief executive of blockchain security firm Blockaid, said reduced randomness on affected devices could make those seeds predictable enough for attackers to recreate the keys without physically accessing the wallet.

Coldcard maker Coinkite and Block linked the vulnerability to the way certain devices generated seeds. Their description pointed to a predictable random-number fallback and a 32-bit reseed in Coldcard firmware. A reseed refreshes the internal state of a random-number generator; if it draws from too small a range of possible values, attackers may be able to test likely outcomes far more quickly than they could against properly generated keys.

A failure in the physical randomness process

Hardware wallets rely on more than simply being disconnected from the internet. Their security also depends on generating secrets with enough entropy, a technical term for unpredictability. A wallet seed generated from a sufficiently random process should be effectively impossible to guess, even for a well-funded attacker with specialized computing resources.

In the Coldcard incident, a coding error reportedly disabled the physical components intended to provide that randomness. The affected firmware then fell back on software-generated values that were substantially more predictable. That would give an attacker a practical route to derive wallet seeds from outside the device and monitor the blockchain for addresses associated with those seeds.

The vulnerability challenges a common assumption around self-custody: moving private keys offline reduces exposure to phishing, malware and exchange breaches, but it cannot compensate for a failure in the device’s underlying cryptography. A hardware wallet can protect a soundly created seed from an internet-connected computer. It cannot protect funds if the seed itself can be reconstructed.

Galaxy Research said more than 7,000 Bitcoin addresses had been targeted. Its estimate of confirmed losses reflects funds already traced as stolen, while its higher projection accounts for activity that remains under review. Galaxy also said several threat actors appear to be exploiting the weakness, suggesting the attack methods or lists of vulnerable seeds may have spread beyond a single group.

Theft moved faster than many holders could react

The reported pace of the attacks underscores the operational risk created by a predictable key-generation process. Once an attacker can identify vulnerable seeds, they do not need to persuade a holder to sign a malicious transaction or obtain access to the physical device. They can simply move Bitcoin from wallets whose private keys they have independently recreated.

One reported sweep drained 1,196 accounts in 41 minutes and took more than $70 million before many affected users had an opportunity to respond. Blockchain transfers are generally irreversible once confirmed, leaving victims with little recourse after compromised funds move through a series of addresses.

The scale also shows why confirmed-loss figures may rise over time. Researchers can identify suspicious clusters and trace known thefts on public blockchains, but associating every address with a specific affected device or wallet holder can take longer. Some holders may also have lost access without yet recognizing that their seed generation was compromised.

Updating alone does not repair an exposed seed

The immediate response for holders of affected devices is more involved than installing new firmware. Software updates may prevent a device from generating additional weak seeds, but they do not add entropy to a seed that was already created under the flawed process.

Users who generated a seed on an affected device would need to create a completely new seed after applying the relevant firmware update and transfer any remaining funds to addresses controlled by that new seed. Restoring an old seed phrase on an updated Coldcard would preserve the original exposure, because the private keys derived from that phrase remain the same.

For users seeking an additional independent source of randomness, physical dice rolls can be used to generate seed material when handled according to a wallet’s documented procedures. The purpose is to avoid relying solely on a potentially faulty random-number source. Any manually created seed must also be backed up carefully, since errors in recording or storing it can permanently block access to funds.

Private-key compromises dominate 2026 losses

Blockaid placed the Coldcard episode within a wider rise in private-key attacks. In its latest security report, the company said nearly 75% of funds lost through cryptocurrency exploits during the first half of 2026 resulted from private-key compromises. Blockaid said total exploit losses exceeded $1 billion over the period as the number of incidents increased.

Ben-Natan said increasingly capable artificial-intelligence tools could make sophisticated attack techniques more accessible. In a hardware-wallet case, automation could help attackers test large numbers of possible seed outcomes, scan blockchain addresses and rapidly broadcast transactions when funds appear.

The Coldcard exploit gives self-custody users a more specific lesson than the familiar advice to keep keys offline: the process that creates a key deserves the same scrutiny as the device that stores it. Hardware isolation remains a meaningful defense, but only when the seed behind it was generated with randomness attackers cannot reproduce.


Protect your coins beyond hardware wallets—learn key crypto safety standards to reduce private-key exploit and wallet-breach risks.

Disclaimer: The content on this page is provided for general informational purposes only and does not represent the views or financial advice of Toobit. We make no guarantees regarding the accuracy or completeness of this information and shall not be held liable for any errors, omissions, or outcomes resulting from its use. Investing in digital assets involves risk; users should independently evaluate their financial situation and the risks involved. For further details, please consult our Terms of Service and Risk Disclosure.

Sign up and trade to earn over 15,000 USDT
Sign up