3 hours ago
Attacker Drains $116M in Bitcoin From Coldcard Addresses
'I Did Everything Right'—AI Warning After $116 Million Bitcoin Hack
Forbes Crypto

Key Point
An attacker moved about 1,816 bitcoin, roughly $116 million, from more than 5,200 addresses generated on Coldcard devices since July 30. Galaxy Research counted the largest sweep at 1,082 bitcoin from 1,196 wallets inside 41 minutes. Coldcard firmware version 4.0.0, shipped in March 2021, carried a build setting that told the device to skip its dedicated hardware randomness chip. Coinkite chief executive Rodolfo Novak urged users who generated seeds with Coldcard wallets to migrate funds using updated best practices. Owners who generated seeds with at least 50 private dice rolls, or who used a strong passphrase, were unaffected.
Why it matters: A wallet entropy failure can turn offline self-custody into hidden key exposure and may weaken trust in hardware wallet security.
Market Sentiment
Cautiously Bearish, Stress-on, Tech-driven, De-risking.
Reason: The reported drain from Coldcard-generated addresses may weaken confidence in self-custody hardware security.
Similar Past Cases
Trust Wallet fixed a WebAssembly vulnerability in its browser extension after the issue led to $170,000 in user losses, according to The Block. The case showed how weak seed generation can leave wallets exposed even without phishing or device theft. (The Block) The key difference is that the Trust Wallet case involved browser extension software, while the current event involves Coldcard hardware wallet seed generation.
Ripple Effect
Entropy doubts can push users away from single-device custody and toward systems with more operational controls. Custody demand may rise if large holders decide that hardware isolation alone does not control hidden implementation risk. If Coinkite publishes its technical review and migration guidance, then containment may depend on whether users rotate vulnerable seeds quickly.
Opportunities & Risks
Opportunities: When Coinkite publishes the technical review, then a clear fault boundary can become a potential confidence-repair signal for hardware wallet users. If migration guidance proves narrow, then self-custody providers with stronger entropy controls may gain user trust.
Risks: If additional waves empty Coldcard-generated addresses, then reducing single-device exposure can limit operational downside. If the technical review shows broader seed-generation exposure, then custody risk may remain elevated across affected users.
This content is an AI-generated summary/analysis for informational purposes only and does not constitute investment advice.