A flaw affecting seed generation on certain Coldcard Mk3 hardware wallets has been tied to a fast-moving bitcoin theft campaign that drained more than 1,300 BTC from thousands of single-signature addresses, according to blockchain analysis shared by Alex Thorn, head of research at Galaxy. The incident has placed older Mk3 wallets created with firmware released between 2021 and 2023 under urgent scrutiny, while Coldcard maker Coinkite says its Mk4, Q and Mk5 devices are not affected.
The theft campaign began on July 31 and expanded through successive sweeps of addresses believed to share vulnerable seed-generation conditions. Early tracking identified about 594 BTC, then valued near $38 million, moved from roughly 500 Coldcard-linked addresses into a consolidated wallet. Later counts compiled from on-chain activity put the toll at 1,367.05 BTC, worth about $88.6 million at the time of that calculation, across 4,585 addresses.
Thorn subsequently said a fourth wave had pushed the total to 1,816 BTC across about 5,200 addresses. That reported wave targeted 462 additional wallets between Bitcoin blocks 960,778 and 960,792, an unusually rapid sequence of approximately 14 sweeps per block.
The targets were predominantly single-signature wallets, where one private key can authorize a transaction. Multisignature arrangements, which require approval from multiple keys, were not included in the affected set identified by Thorn. The distinction has practical consequences: a compromised seed in a single-signature wallet can expose the entire balance, while a multisignature wallet retains protection if its other signing keys were independently generated and secured.
Weak seed generation exposed older Mk3 wallets
Coinkite said the issue originated with a March 2021 firmware migration, beginning with Coldcard Mk3 version 4.0.1 and extending through version 5.0.3, the final supported Mk3 firmware release. The company said a software error caused certain wallet-creation processes to call a weaker software-based random number generator rather than the device’s dedicated hardware random-number generator.
Randomness is central to wallet security. A seed phrase is meant to be generated from an unpredictable pool of random data, making the corresponding private keys effectively impossible to guess. Reduced entropy, the technical term for unpredictability in that data, can make a seed vulnerable to systematic guessing by an attacker who understands the flawed generation process.
According to Coinkite, two code paths used the same function name during the firmware migration. The build process selected the wrong function without producing an error, diverting affected seed generation away from the intended hardware source of randomness. The company said it has changed its build procedures after identifying the problem.
A Bitcoin Core developer using the handle instagibbs said they reproduced the vulnerability on a newly initialized Coldcard Mk3 by relying on button-press counts during device setup. That report added weight to the assessment that the flaw could be exploited without physical access to a victim’s device, provided an attacker could narrow the possible seed-generation inputs.
Coinkite said it destroyed remaining inventory manufactured with vulnerable firmware and paused shipments. Patched firmware prevents newly created seed phrases from using the affected process, according to the company, but updating an old device does not repair a seed phrase generated under the vulnerable versions.
Attacker moved quickly toward larger balances
Chainalysis, which examined the initial theft activity exceeding $38 million, reported that the attacker appeared to prioritize the highest-value wallets. One victim address held about $1.8 million in bitcoin, Chainalysis said.
The speed of the operation indicates that the attacker had a prepared process for identifying and emptying viable targets. Chainalysis found that about $30 million was removed during the first 10 minutes of the campaign, with roughly 500 wallets drained in the first 25 minutes.
Many of the early affected addresses held between 0.15 BTC and 0.26 BTC, according to Thorn’s monitoring. Some of the associated unspent transaction outputs, or UTXOs, had remained untouched for years. Long-dormant wallets may have received less attention from their owners, leaving exposed seed phrases in use after the vulnerable firmware period had passed.
Chainalysis also said the attacker used paid accounts at a blockchain service provider to query information about victim addresses during the operation. The company’s internal logs reportedly matched the timing and order of those queries. Chainalysis said it found no evidence that the service provider knowingly assisted the theft.
As news of the vulnerability spread, Thorn reported that smaller attackers and copycats began attempting to sweep remaining addresses. That creates a difficult environment for affected users: a wallet that has not yet been drained may face competition from multiple parties attempting to derive and spend from the same weak seed.
Existing vulnerable seeds require migration
Coldcard users who created a seed on an Mk3 running firmware 4.0.1 through 5.0.3 have been advised by Coinkite to create a new wallet with a newly generated seed and transfer their funds to that wallet. The replacement wallet should be generated on a device and firmware version outside the affected range.
Users should not assume that installing current firmware alone removes the threat. The security problem lies in the private keys already derived from the old seed; those keys remain the same after an update.
For users whose funds are in an unconfirmed theft transaction, Thorn said replace-by-fee, or RBF, may offer a possible recovery route if the original wallet transaction was created as replaceable. RBF allows a sender to broadcast a replacement transaction spending the same inputs with a higher fee, potentially leading miners to confirm the replacement instead. The option depends on the transaction’s status and wallet configuration, and it is generally a time-sensitive response rather than a remedy for already confirmed thefts.
Coinkite has also pointed to manually supplied entropy, including dice-roll methods, as a way to generate a seed without relying on the affected software path. A user choosing that approach would need to ensure the method is performed correctly and that the resulting backup material is stored securely.
Legal response begins to emerge
Some affected parties are exploring product-liability claims and a potential class action, according to Thomas Braziel, founder and managing partner of 117 Partners. Felipe Ojeda, a Brazilian bitcoin supporter who said he was affected, filed a police report and plans to submit a complaint in Brazil.
The growing loss total puts pressure on Coldcard’s response and on users of older self-custody hardware. Hardware wallets are designed to keep private keys isolated from internet-connected devices, but that protection depends on the keys being generated with sufficient randomness from the start. In this case, the attack has centered on a narrow historical firmware range rather than the Coldcard product line as a whole, yet the scale of the sweeps shows how quickly a seed-generation defect can become an on-chain theft campaign once it is understood and automated.
Worried about wallet exploits like this? Learn key crypto safety practices to better protect your bitcoin from similar security failures.
Disclaimer: The content on this page is provided for general informational purposes only and does not represent the views or financial advice of Toobit. We make no guarantees regarding the accuracy or completeness of this information and shall not be held liable for any errors, omissions, or outcomes resulting from its use. Investing in digital assets involves risk; users should independently evaluate their financial situation and the risks involved. For further details, please consult our Terms of Service and Risk Disclosure.

