A security flaw buried in hardware wallet firmware for more than five years is now being blamed for one of the largest slow-motion Bitcoin thefts researchers have tracked, with losses climbing past $88 million and no clear end in sight.
Galaxy Research says it has traced the theft to a bug in Coldcard, a Bitcoin-only hardware wallet built by Canadian manufacturer Coinkite. The trouble goes back to March 2021, when a firmware update mistakenly pointed the device’s seed-generation process to a software-based pseudorandom number generator instead of the built-in STM32 hardware random number generator it was supposed to use.
According to Coinkite’s own technical writeup, wallets created on the affected Mk2 and Mk3 models using the flawed code ended up with only around 40 bits of genuine randomness behind their seed phrases, a range narrow enough that a determined attacker with sufficient computing resources could eventually work through the possibilities and reconstruct private keys.
The consequences of that four-year-old bug became visible on July 30, when someone swept 1,196 separate Bitcoin addresses in just 41 minutes, pulling out 1,082.65 BTC, worth roughly $70.2 million at the time. Galaxy Research mapped the transactions and confirmed they traced back to the Coldcard vulnerability.
Further, the firm reported a third wave of thefts over the weekend, an additional 207.73 BTC drained, bringing the total it has observed to approximately 1,367 BTC, or about $88.6 million, spread across 4,585 addresses.
Alex Thorn, Galaxy’s head of research, described the situation as far from resolved. Writing on X, he said his team continues to expand its database of both victim and attacker addresses tied to the exploit, and he urged anyone still holding funds in single-signature wallets generated by a Coldcard to move them immediately.
As per the researchers, many of the stolen coins had sat completely dormant before being swept up in the attack, with an average holding period of 3.18 years, suggesting long-forgotten or rarely checked wallets were especially vulnerable.
Galaxy Research said it has also shared roughly 600 suspected attacker addresses with federal investigators, compliance firms, and other cybersecurity teams working across the industry, and credited affected users who came forward with transaction data for helping the firm piece together the scope of the exploit.



