A Coldcard Firmware Flaw Drained 594 BTC in 25 Minutes: We Traced the $38M Sweep On-Chain
— By Tony Rabbit in Markets

About 594.48 BTC (roughly $38 million) was swept out of around 500 Bitcoin wallets in a 25-minute burst on July 30, and the wallets share one trait: seeds generated on an older Coldcard hardware wallet. Coinkite's advisory ties it to a firmware flaw from 2021 that made devices skip their hardware randomness and fall back to predictable keys. We traced the money ourselves: 594.4772 BTC into one collector address, then 562 BTC into a stationary second wallet that has not moved.
In the early hours of July 30, someone drained about 594.48 BTC, worth roughly $38 million, out of around 500 separate Bitcoin wallets in a single, ruthless burst. The wallets had one thing in common: their owners appear to have generated their seed phrases on a Coldcard hardware wallet running old firmware. Coinkite, the company that makes Coldcard, has since published a security advisory warning that a seed-generation flaw dating back to 2021 may have left a class of devices exposed. We traced the money ourselves, and the on-chain picture is as clean as it is alarming.
This is not a phishing story or a fat-fingered approval. If the advisory is right, the private keys were predictable from the moment they were created, which means an attacker did not need to touch the victims at all. They just needed to compute the keys and sweep the coins. That is the nightmare scenario for self-custody, and it is worth walking through exactly what happened and what it does and does not mean for hardware wallet users.
How 594 BTC moved in 25 minutes
We followed the coins on-chain rather than take the numbers on trust. The pattern is a textbook consolidation. Funds from roughly 500 wallets flooded into a first collector address, bc1qnk4z...h8fecp0, which received exactly 594.4772 BTC across 501 transactions. Within the same window the attacker forwarded the bulk of it, 562.02 BTC, into a second address, bc1qq85v...s3fcu9r, that has since sat completely still. About 32 BTC remains in the first wallet. The whole operation, more than 1,300 chunks of Bitcoin pulled in and reconsolidated, fit inside a roughly 25-minute, three-block window.
The flaw: keys that were never really random
According to Coinkite's advisory, the root cause is a build setting that, on affected firmware, caused the device to skip its own hardware random number generator and fall back to a predictable software path. Instead of drawing entropy from a dedicated chip, the seed was effectively seeded by non-secret data: a fixed factory serial number and clock-register values an attacker can narrow down. The result was a seed with far less randomness than the 128 bits a Bitcoin wallet is supposed to have. When the randomness that protects a key collapses, the key stops being a secret and becomes something an attacker can search for.
The company traces the problem to a code change introduced in firmware version 4.0.0, dated around March 1, 2021. That timeline matches the victims almost exactly: the drained wallets were single-signature, each held more than 0.15 BTC, and many had been dormant for years, with coins that first landed anywhere between 2021 and 2026. In other words, the exposure window and the age of the stolen coins line up with the life of the bug.
Who is affected, and who is not
Based on Coinkite's early analysis, the highest risk is for seeds that were generated on a Coldcard Mk3 running firmware 4.0.1 or later. The company has said that, on its early read, the Mk4, Q and Mk5 are not affected, and older Mk1 hardware and firmware 3.2.2 or earlier are outside the window. Coinkite's Tapsigner, Opendime and Satscard products are separate and not implicated. Importantly, the company has not confirmed that this specific flaw is what drained the 500 wallets; it disclosed the issue after detecting that active exploitation was already underway, and the investigation is ongoing. Anyone who owns a Coldcard should read the official advisory and check their exact model and firmware rather than rely on a summary.
The practical takeaway for a potentially affected user is blunt. If your seed was generated on an at-risk Mk3, treat it as compromised and move your funds to a new wallet whose seed was created on unaffected hardware. Coinkite notes that seeds strengthened at creation with a strong, unique passphrase, or with a large number of additional dice rolls, retain meaningful protection, but the safest path is a clean migration rather than betting on a mitigation.
Why this one stings
Hardware wallets are marketed as the answer to exactly this kind of loss: keep your keys offline, and remote attackers cannot reach them. That promise still holds for the vast majority of devices and users. But this incident is a reminder that a hardware wallet is only as strong as the randomness it generates at the very first step, and that a quiet firmware regression can sit dormant for years before someone works out how to weaponize it. The coins are already consolidated and, for now, sitting still in a single address. If this follows the usual script, the next chapter is a slow laundering effort, and it will play out on-chain in public. We will be watching the wallets.
Data note. The on-chain figures (594.4772 BTC into bc1qnk4z...h8fecp0 across 501 transactions, 562.02 BTC forwarded to bc1qq85v...s3fcu9r, ~32 BTC remaining) were read directly by DEXTools News from mempool.space on July 31, 2026. The attribution to a Coldcard seed-generation flaw, the affected models and firmware, and the March 2021 origin reflect Coinkite's security advisory and reporting by CoinDesk and Cryptopolitan; Coinkite has not confirmed that this flaw caused the drain. Dollar values are approximate at a BTC price near $64,000. This is information about a security event and is not financial or security advice; verify your own device against the official advisory.
Frequently asked questions
What happened in the Coldcard 594 BTC theft?
In the early hours of July 30, 2026, an attacker swept about 594.48 BTC (roughly $38 million) from around 500 single-signature Bitcoin wallets in a single 25-minute burst. The wallets appear to share a Coldcard hardware wallet running older firmware. Coinkite published an advisory tying the exposure to a seed-generation flaw introduced in firmware 4.0.0 in March 2021.
What is the root cause of the Coldcard flaw?
Per Coinkite's advisory, a build setting on affected firmware caused the device to skip its hardware random number generator and fall back to a predictable software path, seeded by non-secret data such as the fixed factory serial number and clock-register values. That produced seeds with far less entropy than the intended 128 bits, meaning the private keys could be predicted rather than needing to be stolen.
Which Coldcard models are affected?
On Coinkite's early analysis, the highest risk is for seeds generated on a Coldcard Mk3 running firmware 4.0.1 or later. The company has said the Mk4, Q and Mk5 appear unaffected on early review, and Mk1 hardware and firmware 3.2.2 or earlier are outside the window. Tapsigner, Opendime and Satscard are separate. Coinkite has not confirmed this flaw caused the drain and is still investigating, so owners should check the official advisory for their exact device.
What should Coldcard owners do now?
If your seed was generated on an at-risk Mk3, treat it as potentially compromised and move funds to a new wallet whose seed was created on unaffected hardware. Coinkite notes that seeds strengthened at creation with a strong unique passphrase or many extra dice rolls retain meaningful protection, but a clean migration is the safest path. Verify your model and firmware against the official Coinkite advisory rather than relying on a summary.