More than 1,082 bitcoin, worth about $70 million, were drained from over a thousand Coldcard hardware wallets in under an hour, without physical access, passwords, or phishing, affecting long-term holders relying on cold storage. Coinkite traced the theft to a five-year-old firmware bug that bypassed the hardware random number generator, creating weak, partly predictable seed phrases across multiple Coldcard models, allowing attackers to systematically brute-force affected wallets. Coinkite has released patched firmware and urged users to treat existing seeds as compromised, generate new ones, and move funds. The incident shook confidence in self-custody, while leaving custodial exchange users largely untouched.
This update represents a notable development in the Crypto sector. Organizations and founders tracking this space should evaluate potential strategic and technical implications on their operations.