3 hours ago

Coldcard Exploit Drains $38M in BTC From 500 Dormant Wallets

Coldcard attack: 25 minutes, 500 wallets, $38M in BTC gone

Protos

Key Point

A seed phrase exploit targeting Coldcard hardware wallets drained almost 600 BTC, worth $38 million, from roughly 500 dormant wallets yesterday. The attack moved BTC from 500 single-signature addresses into one address in 25 minutes, and reports suggest the exploit will likely continue. Coinkite confirmed that seed generation in its Mk3 wallet and updated versions beyond March 2021 version 4.0.1 may not have been random at all. Coldcard initially said Mk3 devices were at risk and Mk4, Q, and Mk5 were not affected based on early analysis. Block traced the bug to a mis-written compile-time check and found a smaller, real version of the same flaw in newer devices.

Why it matters: Hardware wallet exploits can weaken self-custody confidence and may push users to move funds if vulnerability scope remains uncertain.

Market Sentiment

Bearish, Stress-on, Event-driven, De-risking.

Reason: The $38 million BTC theft from dormant Coldcard wallets may weaken confidence in self-custody security.

Similar Past Cases

In 2022, Solana ecosystem teams traced a wallet-draining incident to Slope, and almost 8,000 wallets had been affected. Slope recommended that users create new seed phrase wallets and transfer assets to them. (The Block) The difference is that the Slope case involved software wallet exposure, while the Coldcard case centers on hardware wallet seed generation.

Ripple Effect

The direct channel is self-custody trust, because weak seed generation can turn dormant wallets into active loss risk. If reports of continuing exploitation prove correct, then affected users may rush to migrate funds and custody tools may face higher scrutiny. If newer devices remain within the vulnerability scope, then the security concern may spread beyond Mk3 users.

Opportunities & Risks

Opportunities: If Coinkite or Block narrows the affected firmware set, then moving funds only from devices inside that scope limits operational risk. If exploit activity stops after remediation details are published, then confidence in unaffected devices may stabilize.

Risks: If additional drains appear from the same vulnerability, then reducing reliance on affected hardware wallets becomes a practical risk-control signal. If newer devices remain inside the flaw scope, then delaying seed rotation leaves wallets exposed to continued compromise.

This content is an AI-generated summary/analysis for informational purposes only and does not constitute investment advice.