A Hidden Flaw, Five Years in the Making
A software vulnerability buried inside one of the cryptocurrency industry's most trusted hardware wallets has resulted in the theft of nearly $90 million in Bitcoin, exposing thousands of users and triggering urgent warnings across the industry.
The flaw traces back to March 2021, when Canadian manufacturer Coinkite changed the seed-generation process in its Coldcard wallet as part of integrating a new cryptographic library [2]. That migration inadvertently routed wallet creation through a predictable random number generator (PRNG) already present in the codebase, rather than the true random number generator (TRNG) Coinkite had intentionally designed [2]. The result: for more than five years, newly created Coldcard wallets were generating recovery phrases that were far more predictable than users — or the company itself — realized.
"The bulk of randomness on the COLDCARD was coming from a PRNG that I didn't know was actually in the source code base," Coinkite acknowledged in its postmortem, adding that its intended TRNG "was being used, but just by chance, and only for less important things" [2].
The Attack: 41 Minutes, $70 Million
The vulnerability was not theoretical for long. On July 30, attackers drained more than 1,000 Bitcoin from 1,196 digital wallets in just 41 minutes, with initial losses estimated at roughly $70 million [1]. Galaxy Research, which analyzed the blockchain activity, subsequently identified two additional suspected waves of suspicious activity, pushing estimated total losses to nearly $89 million [1]. By Sunday, the number of impacted addresses had climbed to over 4,500, with losses approaching $90 million [2].
Galaxy cautioned that its findings are based on blockchain analysis and that it has not confirmed every affected wallet was created using the vulnerable software [1].
The attack's speed and precision underscored just how exploitable the flaw had become. Because the seed phrase — the master key to a wallet — was generated using the chip's serial number and a timer rather than truly random data, sophisticated attackers could reconstruct it without ever physically handling the device [1][2].
What Coinkite Is Telling Users to Do Right Now
Coinkite has released a firmware update, but it comes with a critical caveat: installing it does not fix wallets that were already created with the flawed software [1]. The weakness is embedded in the recovery phrase itself, not the physical hardware.
"Updating the firmware does not repair a seed that was generated by affected firmware," the company stated in its security advisory. "A new seed must be generated and the funds migrated to the new wallet" [1].
Coinkite also warned that transferring the same recovery phrase to a different wallet device offers no protection, since the vulnerability follows the phrase, not the hardware [1]. Users who created their wallet using at least 50 private dice rolls are not affected by this specific flaw, but Coinkite recommends that anyone unsure of their setup generate a new recovery phrase immediately as a precaution [1].
The company has halted all device shipments since confirming the vulnerability and has destroyed all remaining units at its facilities containing the affected firmware [2]. Users with affected devices, however, have been advised not to dispose of them, as the hardware "may become essential if funds are recovered" [2].
A CEO's Public Apology — and a Race Against Time
Coinkite CEO Rodolfo Novak issued a public apology on X, describing his company as "heartbroken" and accepting full accountability. "I'm sorry and I'm devastated," Novak wrote, urging customers to act without delay: "If you generated a seed using a Coldcard wallet, move your funds now, using our updated best practices, before reading further" [1].
Novak also appealed to the broader community to help spread the warning, noting that "some affected users may not be watching social media right now, and every hour matters" [1]. Attacks, researchers stressed, are believed to be ongoing [1][2].
Jan3 CEO Samson Mow echoed the urgency on X: "If you're using a COLDCARD, any version firmware or MK, migrate your funds immediately. If you know someone who is, let them know ASAP" [1].
Coinkite said it is cooperating with blockchain investigators and law enforcement across multiple jurisdictions and will help affected customers file police reports or insurance claims [1][2].
An Industry-Wide Testing Gap
Beyond the immediate crisis, security experts say the incident exposes a structural weakness in how hardware wallets are evaluated before they reach consumers.
Kraken chief security officer Nick Percoco called the episode a "wake-up call" for the entire hardware wallet industry, arguing that independent testing must verify that an approved entropy source is the one actually used by production firmware — not merely that the approved code exists somewhere in the codebase [2]. The Coldcard flaw persisted for five years in part because code reviews confirmed the TRNG code was present and functional, but no process checked whether it was actually being called [2].
"Consumers are asked to trust a manufacturer's implementation of the single most critical function in the system, with no independent verification that the approved entropy path is the one actually executing," Percoco said [2].
He pointed to established standards in other industries — including NIST SP 800-90B, a U.S. government standard for validating physical true random number generators, and BSI AIS-31, a German Federal Office for Information Security equivalent — as benchmarks the hardware wallet sector currently lacks [2]. "The payments industry does not let PIN entry devices ship without independent lab testing. The US government does not accept cryptographic modules without entropy source validation. Digital asset self-custody should not be the exception," Percoco said [2].
This analysis represents Percoco's professional assessment of industry practices and is not a settled regulatory or technical determination.
In response to the broader conversation, Ledger stated that its TRNG is evaluated under AIS-31 with PTG.2 certification and that its devices hold ANSSI's CSPN Certification from France's national cybersecurity agency — pointing to the kind of third-party validation Percoco argues should become standard [2].
Block, whose Bitcoin Engineering and Security team published the initial advisory on the Coldcard vulnerability, emphasized that none of its own products or customers are affected [1]. Separately, developers of Jack Dorsey's Bitkey wallet said they are investigating a different reported issue with their product but are not advising users to stop using it, describing the reported risk as requiring "exceptional circumstances" to exploit [1].
What to Watch Next
Coinkite has promised a detailed technical postmortem once its internal investigation is complete, and says it will not speculate on the full scope of affected users until that review concludes [1]. Law enforcement coordination across multiple jurisdictions is underway [2].
The key questions going forward: whether stolen funds can be traced and recovered, how many additional wallets remain at risk as attacks continue, and whether this incident becomes the catalyst for mandatory independent entropy-validation standards across the hardware wallet industry.
If you hold Bitcoin on any Coldcard device and have not yet migrated your funds, security researchers and the manufacturer are unanimous — do it now.


