Bitcoin Vault Bug Opens $89M Heist

Bitcoin coins with a fluctuating price chart background.
$89M HEIST BOMBSHELL

A five-year-old bug in a “safe” bitcoin vault quietly turned thousands of Coldcard wallets into open treasure chests — and someone finally walked off with about $89 million.

Story Snapshot

  • About 1,367 bitcoin were stolen from 4,585 Coldcard-linked addresses in three fast waves.
  • The attacker did not touch a single device; they cracked weakened seed phrases offline.
  • A firmware bug dating back to 2021 quietly broke Coldcard’s core promise of strong randomness.
  • Security teams say every still-vulnerable wallet is likely to be emptied sooner or later.

How a trusted “vault” turned into a soft target

Coldcard sold itself as the gold standard for air-gapped bitcoin storage, the device you buy when you never want to worry again. That illusion shattered between July 30 and early August, when blockchain analysts watched one of the largest hardware wallet failures in bitcoin history unfold in real time.

Galaxy Research and other teams traced roughly 1,367 bitcoin, close to $89 million, drained from 4,585 addresses linked to Coldcard-generated seeds.

The key detail that should make any self-custody user sit up straight is this: the thief never needed physical access. No malware. No phishing email. No seed phrase stolen from a photo on your phone. The attack worked because many Coldcard devices did not generate truly random wallet seeds.

Once an attacker understood that weakness, they could recreate those “random” secrets at home, test them against the blockchain, and move funds away while owners slept.

The three waves of the $89 million Coldcard exploit

The first shock came on July 30. In about 41 minutes, an unknown attacker swept 1,082.65 bitcoin from 1,196 addresses, worth about $70 million at the time.

On-chain watchers saw the coins jump from hundreds of dormant wallets into a handful of attacker-controlled addresses, with no pattern of normal user activity.

Researchers quickly linked the victims by how their seeds were generated, and Coldcard’s name moved from “most secure” to “main suspect” almost overnight.

The second wave followed days later, hitting a much larger number of smaller wallets. Galaxy Research and others reported an additional sweep of tens of bitcoin across more than a thousand addresses, then a third wave that drained about 208 bitcoin from 1,912 wallets.

When analysts added up the three waves, the total reached about 1,367 bitcoin. That placed the Coldcard incident on par with some of the biggest centralized exchange failures, but this time the weak link was supposed to be the safe, not the casino.

The firmware bug that broke bitcoin’s “air gap”

The heart of the failure sits in a single engineering mistake. Since around March 2021, some Coldcard firmware builds quietly turned off the device’s hardware random number generator and fell back to a software-based one.

Hardware randomness pulls noise from physical electronics and is very hard to predict. The software fallback Coldcard used, by contrast, followed a deterministic pattern. Once you know the pattern, you can guess the outputs. And if those outputs feed your wallet seed, your “secret” is no longer a secret.

Security teams at Block and Galaxy describe the bug as effectively collapsing the strength of Coldcard seed phrases from a huge search space down to something a dedicated attacker can brute-force offline.

Here, a configuration line buried in a build flipped that promise on its head. It did so without warning users, who kept trusting a product that no longer delivered the core security they thought they were buying.

Who got hit and why it matters far beyond Coldcard

The victims span classic “set and forget” self-custody users. Many addresses had sat untouched for years, holding whole coins bought in earlier cycles. That dormancy made them perfect targets once their seeds were guessable.

Analysts noted that the first wave targeted higher-value wallets, then later waves sprayed across more addresses with smaller balances, suggesting the attacker first picked the low-hanging fruit and then widened the net.

From this angle, this incident undercuts a lazy habit many bitcoin holders have adopted: outsource everything to a brand and assume the brand never fails. Bitcoin’s entire pitch is that you take personal responsibility and remove middlemen.

Yet here, thousands trusted a single hardware maker’s unseen firmware choices. When that maker shipped a quiet bug, the result looked a lot like the very custodial failures Bitcoin was meant to avoid, just with a more technical backstory.

What Coldcard and users did once the damage surfaced

Coldcard’s parent company, Coinkite, issued a security advisory after the first sweep, warning that seeds created on certain Mk3 and newer firmware versions since 2021 might be unsafe. The company pushed patched firmware within days, urged users to update, and told those with affected seeds to move funds to new wallets.

But on-chain data shows that many vulnerable addresses remained untouched even after public warnings, leaving a long tail of risk that analysts expect attackers to harvest over time.

Galaxy’s team has already hinted at possible additional waves, and Yahoo Finance reported researchers now treat every still-vulnerable wallet as a “when, not if” target. That blunt framing fits reality: once a bug that weakens seed randomness is public, any skilled attacker can copy the technique.

For holders, the lesson is harsh but simple. If your long-term savings depend on one small device, you cannot ignore firmware notices and hope problems stay theoretical. The chain settles every bet.

Sources:

foxbusiness.com, thehackernews.com, coindesk.com, crypto.news, techspot.com, cryptopolitan.com, youtube.com, kucoin.com, finance.yahoo.com