A flaw turned Coldcard’s “unguessable” seeds into guessable ones. Thieves swept about 594 bitcoin in 25 minutes. Who is exposed, and what to do now.
Between 01:31 and 01:56 UTC on Friday, someone emptied about 594 bitcoin — roughly $38 million — out of some 500 separate wallets in a single 25-minute sweep. The coins moved in 1,324 chunks across 500 transactions, all inside a three-block window, before 562 BTC were consolidated into one address that has not moved since. Every drained wallet was single-signature. Every one held more than 0.15 BTC. Many had sat untouched for years.
The victims were not careless. They had done the thing bitcoiners are told to do: taken their coins off exchanges and onto a Coldcard, one of the most respected hardware wallets in the business, built by Canadian firm Coinkite. The betrayal came from inside the device.
A wallet’s seed — the secret phrase that controls the money — is supposed to be drawn at random from a pool so vast that guessing is hopeless. Coldcard’s firmware stopped doing that. According to a report from Block’s bitcoin engineering and security team, a build setting told the device to skip its own hardware random-number generator, and a check in a supporting library tested only whether that setting existed, not whether it was switched on.
Key generation quietly fell through to a basic software substitute seeded from the chip’s serial number and clock registers. None of those are secrets: the serial number is fixed factory metadata, and the clock values are timing state an attacker can narrow down. Seeds that should have carried 128 bits of entropy were built with as few as about 40. Block traced the flaw to a commit dated March 1, 2021, shipped in firmware 4.0.0 that month — which is why the stolen coins span 2021 to 2026, matching the bug’s age almost exactly.
The exposure runs past ordinary seeds. The same weak generator produced Coldcard’s paper-wallet keys, seed-splitting masks, device-cloning keys and Key Teleport transfers. Anywhere the device reached for randomness, it may have reached into a shallow pool.
The confirmed danger zone is the Coldcard Mk3 running firmware 4.0.1 (March 2021) through 4.1.9. If you generated a 12- or 24-word seed on that device and did not add your own dice-roll entropy or a BIP39 passphrase, treat your funds as at risk and move them.
Two caveats matter. Coinkite says that, based on early analysis, the newer Mk4, Q and Mk5 devices are not affected — but the company still issued fixed firmware for every model and urged all users to update. And both Coinkite and Block describe their analyses as preliminary; Block published before finishing its testing because the theft was already underway. Estimates of the total haul have since climbed past $70 million as more wallets are swept.
The one group that can breathe easier: anyone who rolled their own dice for entropy when setting up the wallet, or who protected it with a BIP39 passphrase. That user-supplied randomness sits outside the broken code path.
Multi-signature users are not automatically safe, and moving funds can be the moment of danger. Core contributor Peter Todd flagged the edge case: a 2-of-3 wallet with two Coldcards and one clean device looks protected — until you spend. The instant a transaction reveals the wallet’s script, previously hidden behind an address hash, an attacker who holds the two compromised keys learns enough to build a competing, higher-fee transaction and race you for the coins.
There is a defense. If you have never reused the address, MARA’s private-mempool mining service, Slipstream, can keep the transaction — and its public keys — secret until it is already buried in a block, denying the attacker the window. If you have reused addresses, that protection is gone; just move the funds as fast as you can.
The victims did everything right. The randomness underneath them was wrong.
What unsettles builders is not just the bug but how it was likely found. Coldcard’s firmware is open source, and Coinkite co-founder NVK argues an AI model probably read it to spot the latent weakness. “AI-assisted code review can now find latent bugs at a speed that is outpacing even the industry’s most seasoned experts,” he wrote. “If your firmware is open-source or has ever been public, assume it’s already being read by attackers and defenders alike.”
That is the wider lesson of the week. A $70-million bounty now hangs over every open codebase that touches private keys, and the tools to claim it are cheap and improving. Other wallet makers — especially open-source projects that generate key material — should expect to be probed next. The likely response is defensive: multi-vendor, multi-key setups that spread risk across separate codebases, more user-supplied dice entropy, and audits run against the same frontier models the attackers use.
None of this is an argument against self-custody, whatever some headlines suggest. Custodians and ETFs have their own single points of failure; they simply hide them behind a counterparty. The Coldcard failure is an argument for better self-custody — simpler, auditable tools and randomness a user can verify with their own hands.
A five-year-old randomness bug let attackers guess seeds that were supposed to be unguessable, and drain tens of millions from Coldcard owners in minutes. If you set up a Coldcard Mk3 since March 2021 without your own dice entropy or a passphrase, update the firmware, make a fresh wallet, and move your coins today. The deeper shift is that AI can now audit open code faster than its authors can — and everyone building self-custody just got put on notice.
Editor’s note: figures are preliminary and were rising at press time; the initial ~594 BTC / $38M sweep had grown past an estimated $70M as reporting continued. Firmware version numbers and the Mk4/Q/Mk5 “unaffected” status reflect Coinkite’s and Block’s early analyses — verify against the official Coinkite advisory before acting. Nothing here is financial or security advice; when funds are at stake, confirm steps independently.
Free. Five minutes. No hype.
Subscribe free