A flaw that shipped in 2021 let thieves guess the seed phrases behind one of bitcoin’s most trusted hardware wallets. Days later, a rival maker patched its own severe bug.
The point of a hardware wallet is that no one can guess your keys. For thousands of Coldcard owners, that promise broke on July 31, when thieves began emptying wallets that had sat untouched for years. By August 16, Galaxy Research put the confirmed losses at more than $115 million in bitcoin, measured at the price when each coin was stolen, and said the true figure could pass $130 million as it keeps counting.
The flaw sits in the most sensitive step a wallet performs: generating the random number that becomes your seed phrase. In Coldcard Mk3 devices, starting with firmware version 4.0.1 released in March 2021, seed generation quietly fell back to a weak software pseudorandom number generator instead of the hardware true-random generator the device was built around. Weak randomness means guessable keys. Attackers did not need to steal the devices or break their secure chips — they could reconstruct the seeds from afar and sweep the coins.
Coinkite, the Toronto company behind Coldcard, said the bug “silently went unnoticed” and that “its potential impact grew with every release” of its products — each new firmware carried the flaw forward to more users. The company first warned holders on July 31, days after the thefts began, and urged them either to update immediately or move their coins off the device entirely. Unlike a normal patch, some affected users cannot simply upgrade; a seed generated by a compromised process stays weak, so the safe move is to migrate funds to a freshly generated wallet.
Galaxy Research, which has been tracking the on-chain trail, estimates that at least 15 separate attackers were exploiting the bug independently — not one crew, but a scramble once the weakness became known. The firm said it had spoken with more than 200 victims to support them and gather intelligence on the thieves. On August 18, Bitcoin Magazine reported that investigators may have identified the “wave one” attacker and that the case had drawn the FBI’s attention.
What makes the episode sting is who lost. According to Galaxy’s analysis, the typical stolen coin had sat untouched for about three and a half years, and a striking 88% of the pilfered funds were at least a year old. This was not hot money on an exchange; it was long-term savings, held in cold storage by people who did everything the orthodoxy told them to do — buy a dedicated device, keep the keys off the internet, hold their own coins.
The Coldcard disaster was still unfolding when a second maker came forward. On August 17, the Swiss manufacturer BitBox released a firmware update it called “Dixence” and disclosed that internal audits had turned up multiple severe vulnerabilities. One would have let an attacker manipulate a user into installing malicious firmware; another, a memory-corruption flaw, could enable arbitrary code execution and the subsequent installation of malicious firmware, opening the door to fund loss.
BitBox said the memory-corruption issue affected its Multi edition and that the Bitcoin-only edition was not vulnerable, because its firmware does not contain the offending code. Crucially, the company said there were no reports of stolen funds and that users did not need to migrate — only to update through the official BitBoxApp, ideally via the in-app prompt rather than by hunting for a download. It was a patch, not a post-mortem. But the timing underscored a point the Coldcard hack had already made: the device is only as trustworthy as the code running inside it, and that code is written by humans.
Self-custody removes the middleman. That is the entire pitch: no bank to freeze your account, no exchange to go bankrupt with your coins, no counterparty at all. But removing the middleman also removes the safety net. When a bank ships buggy software, deposit insurance and chargebacks absorb the damage. When a hardware wallet ships buggy software, the loss is final and it is yours.
The immediate fallout has been a quiet migration. Coinkite and other Bitcoiners spent the past three weeks urging Coldcard owners to move their funds, and some spooked holders have done the thing self-custody was meant to avoid — sent their coins back to exchanges, where at least a company stands behind the balance. That is a rational response to fear, and also a small defeat for the idea that individuals can safely be their own bank.
None of this is a flaw in bitcoin the protocol. The network kept producing blocks; the ledger recorded every theft with perfect fidelity. The break was in the tools people use to touch it. As the industry has professionalized, those tools have multiplied — hardware wallets, payment servers, custodial apps — and each is a new surface where a single mistake can cost strangers their savings. The Coldcard flaw hid in plain sight for more than four years before anyone with bad intentions found it.
Why it matters: bitcoin hands you full control of your money, and full responsibility for the code that guards it — a bargain that only holds when the code is sound.
Loss figures are Galaxy Research estimates based on bitcoin’s price at the time each coin was stolen and remain provisional; the firm has said totals could exceed $130 million. Coldcard is made by Coinkite (Toronto); BitBox by Shift Crypto (Switzerland). Informational only — not financial advice.
Free. Five minutes. No hype.
Subscribe free