Coldcard Firmware Flaw Drains $38M From 500 Wallets
- Bitcoin
- Security
- Key Compromise

Attackers used a Coinkite Coldcard firmware bug to generate candidate seeds offline, derive addresses, and sweep funds from single-signature wallets created after the vulnerable update. Roughly 1,367 BTC worth $38M left 500 wallets in the first confirmed mass hardware exploit of its kind. CT spent the week debating whether any hardware wallet can ever be trusted again after the offline seed generation method was detailed.
Incident Details
- Type
- KEY COMPROMISE
- Funds Lost
- $38M
- Status
- Ongoing
CT debates hardware wallet trust; Bitcoin sees worst monthly performance in years