The Grey Terminal
WHERE CODE MEETS CAPITAL
Loading prices…
Powered by CoinGecko
Bitcoin

What Really Happened Behind the Largest Verified Coldcard Bitcoin Theft That Drained 594.48 BTC From 500 Wallets in 15 Minutes

What Really Happened Behind the Largest Verified Coldcard Bitcoin Theft That Drained 594.48 BTC From 500 Wallets in 15 Minutes

Nearly 600 bitcoin disappeared from hundreds of Coldcard hardware wallets in just over 15 minutes last week, but investigators say the attacker never breached the devices.

Key Takeaways
  • A criminal actor drains 594.48 BTC from 500 Coldcard wallets by recreating a flawed recovery-seed generator in vulnerable 2021 firmware.
  • The attacker exploits an entropy collapse from 128 bits to 40 bits to sweep millions in 15 minutes and 18 seconds.
  • Coinkite identifies the firmware build error while researchers warn that hardware security features cannot protect wallets created with predictable recovery seeds.
Listen to this article
READY

An on-chain reconstruction by cybersecurity researchers at International Cyber Digest (ICD) found the wallets were emptied after the attacker recreated a flawed recovery-seed generator introduced in vulnerable Coldcard firmware. By generating every seed the affected software could plausibly produce and matching the resulting addresses against the public Bitcoin blockchain, the attacker identified funded wallets before sweeping 594.48 BTC from 500 addresses.

The reconstruction offers the clearest account yet of what researchers describe as the largest verified Coldcard wallet theft publicly traced on-chain. It also shifts attention away from the wallets themselves and towards a software build error that quietly reduced the randomness protecting newly created recovery seeds.

Attack Reconstructed On-Chain

Researchers said the theft unfolded across four consecutive Bitcoin blocks on 30 July, draining 594.48 BTC from 500 single-signature wallets in 15 minutes and 18 seconds.

The stolen funds were collected through 500 transactions involving 1,324 unspent transaction outputs before being consolidated into a single collection address. Most of the bitcoin was later transferred into another address holding approximately 562 BTC, where it remained at the time of publication.

Advertisement · Press Release

Have a development worth tracking?

Share product launches, funding announcements, partnerships, research findings and market developments with The Grey Terminal's readership.

→ Submit a Press Release

The affected wallets contained coins received between 2021 and 2026, matching the period during which vulnerable firmware versions were distributed, researchers said.

The transaction pattern showed no evidence of manual selection. Instead, ICD concluded the attacker identified valid private keys first and then automatically emptied every funded wallet linked to them.

Predictable Seeds Opened the Door

According to researchers, the attacker did not steal recovery phrases, bypass PIN protection or compromise Coldcard’s secure element.

Instead, they rebuilt the vulnerable seed-generation process using publicly available firmware.

The reconstructed generator produced the limited pool of recovery seeds that affected Coldcard devices could ever create. Each candidate seed generated a corresponding set of Bitcoin addresses, which the attacker compared against publicly visible blockchain records.

Every address containing funds immediately became a live target because the recreated recovery seed also reproduced the wallet’s private key.

Researchers said the attack relied entirely on offline computation and publicly available blockchain data.

Build Error Reduced Wallet Entropy

Coldcard manufacturer Coinkite traced the vulnerability to firmware released in March 2021.

The affected software was intended to generate recovery seeds using hardware-derived randomness. A build configuration error instead caused certain firmware versions to rely largely on predictable software values generated from device state and internal timing information.

Researchers estimated that affected Coldcard Mk3 firmware produced roughly 40 bits of entropy instead of the intended 128 bits.

That reduction transformed an effectively impossible search problem into one modern computing hardware could realistically enumerate.

Engineers at Block independently reviewed the vulnerable code path and confirmed the entropy collapse described by Coinkite.

Device Security Was Never Bypassed

The investigation found no weakness in Bitcoin’s cryptography.

Nor did the attacker defeat Coldcard’s PIN protection, secure element or air-gapped design.

Those protections continued to function as intended.

Researchers said the flaw existed before those defences came into play.

Once a predictable recovery seed had been recreated, every security feature on the device continued protecting a private key that the attacker already possessed independently.

ICD characterised the incident as a failure of randomness rather than encryption.

Which Wallets Face the Highest Risk

Coinkite said Coldcard Mk3 wallets that generated new recovery seeds using firmware released after March 2021 face the highest confirmed risk.

Later Coldcard models incorporated additional entropy sources, although some firmware remained below the intended security threshold until patched releases became available.

The company said users who generated wallets using substantial independently supplied dice entropy or protected funds with strong BIP-39 passphrases face significantly lower risk because those additional secrets cannot be reproduced through the vulnerable algorithm.

Coinkite has advised affected users to update to patched firmware, generate an entirely new recovery seed and migrate funds into a freshly created wallet.

Updating firmware alone does not secure wallets created with vulnerable recovery seeds because those private keys remain unchanged.

Why Researchers Say This Theft Stands Apart

Most cryptocurrency thefts begin with phishing attacks, malicious software or compromised exchanges.

ICD’s reconstruction points to a different sequence.

The attacker never needed to contact victims or interact with their devices. The vulnerable firmware produced a limited number of possible recovery seeds, allowing private keys to be regenerated offline and matched against publicly funded Bitcoin addresses.

Researchers said the attack illustrates how a failure during key generation can undermine every protection that follows, even when the wallet itself remains uncompromised.

TERMINAL LAYER

Activate Terminal Layer

Structural analysis of the systems, pressures, and stakeholders behind this story.

FAQ

Frequently Asked Questions

01

What is the Coldcard entropy vulnerability?

This vulnerability is a software build error in Coinkite firmware that reduced the randomness of newly generated recovery seeds. Researchers at International Cyber Digest found affected Mk3 devices produced only 40 bits of entropy instead of 128 bits. This reduction allows attackers to recalculate private keys offline by matching predicted addresses against the Bitcoin blockchain.
02

Why does this theft matter for the hardware wallet industry?

The incident proves that hardware-level protections like secure elements are useless if the initial seed generation process is mathematically flawed. International Cyber Digest verified that 594.48 BTC disappeared across 500 unique addresses in under 16 minutes. It forces a industry-wide re-evaluation of how firmware randomness is audited and verified before public distribution.
03

How did the attacker execute the 594.48 BTC theft?

The attacker rebuilt the faulty Coinkite generator using public firmware to enumerate every possible recovery seed the software could produce. These seeds generated a set of candidate addresses that were cross-referenced with funded wallets on the public Bitcoin ledger. Once a match appeared, the attacker used the derived private key to sweep funds automatically into a single collection address.
04

What are the risks for current Coldcard Mk3 users?

Users who generated recovery seeds using firmware released after March 2021 face a high risk of total asset loss. Coinkite warns that standard PIN protection and air-gapped designs do not prevent this specific type of offline key regeneration. Wallets remain vulnerable until owners move their funds to a completely new seed generated with patched software or dice rolls.
05

How can investors secure their Bitcoin against predictable seed attacks?

Investors must migrate funds to new wallets created using external entropy sources such as physical dice rolls or strong BIP-39 passphrases. These additional layers of randomness ensure that a private key cannot be reproduced solely through a firmware algorithm. Developers at Block recommend immediate firmware updates and a total rotation of all legacy recovery phrases.

You Might Also Like

THE GREY TERMINAL
🛡
Alex Reeve

Alex Reeve is a contributing writer for The Grey Terminal Her articles provide timely insights and analysis across these interconnected industries, including regulatory updates, market trends, token economics, institutional developments, platform innovations, stablecoins, meme coins, policy shifts, and the latest advancements in AI, applications, tools, models, and their broader implications for technology and markets.

The views and opinions expressed by the author in this article are her own and do not necessarily reflect the official position of The Grey Terminal, its management, editors, or affiliates. This content is provided for informational and educational purposes only and does not constitute financial, investment, legal, or tax advice. Readers should conduct their own research and consult qualified professionals before making any decisions related to digital assets, cryptocurrencies, or financial matters. The Grey Terminal and its contributors are not responsible for any losses incurred from reliance on this information.