Security

Coldcard Firmware Bug Let Attackers Drain 594 BTC From Hardware Wallets

A firmware bug in Coldcard Mk3 hardware wallets skipped hardware RNG during key generation, allowing attackers to sweep 594 BTC ($38M) from ~500 wallets in 25 minutes.
Coldcard Firmware Bug Let Attackers Drain 594 BTC From Hardware Wallets

TL;DR - A firmware bug in Coldcard Mk3 hardware wallets caused the device to skip its hardware random number generator during key generation, falling back to predictable software-generated keys. Attackers exploited this to sweep 594 BTC (approximately $38 million) from around 500 wallets in a 25-minute window early Friday morning. The vulnerability was introduced in firmware version 4.0.0 in March 2021 and affected Mk3 devices running firmware 4.0.1 and later. Mk4, Q, and Mk5 devices are not affected.

Quick Answer: On Friday, July 25, 2026, attackers drained 594 BTC ($38 million) from approximately 500 Coldcard Mk3 hardware wallets between 01:31 and 01:56 UTC. The root cause was a firmware bug introduced in version 4.0.0 (March 2021) that skipped the hardware random number generator during key generation. Keys were generated using predictable software inputs - the chip's serial number and clock registers. Block (formerly Square) discovered and disclosed the vulnerability. Mk4, Q, and Mk5 devices are not affected according to Coinkite.

What Happened?

Between 01:31 and 01:56 UTC on Friday, someone swept 594 BTC from roughly 500 wallets in a coordinated, automated attack. The transactions hit the blockchain in 1,324 chunks across 500 transactions, compressed into a three-block window. Within hours, 562 BTC was consolidated into a single address that has not moved since.

Every affected wallet shared the same profile: single-signature, holding more than 0.15 BTC, and generated on a Coldcard Mk3 running firmware version 4.0.1 or later. Many had been dormant for years.

How Did the RNG Bug Work?

Coldcard hardware wallets use a dedicated hardware random number generator (TRNG) built into the microcontroller chip to produce the entropy that seeds private keys. Hardware RNG produces true randomness from physical processes - electrical noise, thermal fluctuations - that can't be predicted or reproduced.

Firmware version 4.0.0, released by Coinkite in March 2021, introduced a code path that skipped the hardware RNG under certain conditions. When this happened, the device fell back to a software-based pseudo-random number generator seeded by two values: the chip's serial number and its clock registers at boot time.

A serial number is unique to each chip but not secret - it can be read by anyone with physical or firmware-level access. Clock registers at boot are deterministic enough to narrow the search space dramatically. Together, they produce keys that look random to the user but are reproducible by anyone who understands the seeding mechanism.

The bug didn't affect every Mk3 device. It required firmware 4.0.1 or later (4.0.0 introduced the code path but the fallback behavior manifested in subsequent updates). Coinkite's Mk4, Q, and Mk5 devices use a different microcontroller architecture and are not affected.

Who Discovered It?

Block, the payments company formerly known as Square, discovered and reported the vulnerability. They published the disclosure without completing full proof-of-concept testing because exploitation was already underway - the sweep happened before the disclosure was finalized.

The attackers either independently discovered the same bug or had access to information about it before the public disclosure. The 25-minute sweep across 500 wallets required pre-computed key material and automated transaction construction.

What Else Is Affected?

The RNG bug extends beyond wallet key generation. Coinkite's firmware uses the same random number generator for:

  • Paper wallet private keys generated on Mk3 devices
  • Seed-splitting masks used in backup schemes
  • Device cloning keys for creating backup devices
  • Key Teleport transfers between devices

Any of these operations performed on an affected Mk3 running firmware 4.0.1+ may have used predictable entropy. Users who generated paper wallets or split seeds on affected devices should treat those keys as potentially compromised.

What Should Coldcard Mk3 Owners Do?

If you hold bitcoin on a Coldcard Mk3 that was set up with firmware 4.0.1 or later:

  1. Move funds immediately to a wallet generated on a different device
  2. Do not simply update firmware - the keys already generated with weak entropy remain compromised regardless of firmware updates
  3. Generate new keys on a Mk4, Q, Mk5, or another hardware wallet from a different manufacturer
  4. If you used your Mk3 to generate paper wallets or split seeds, treat those as compromised too

For users considering alternatives, our bitcoin custody comparison covers the range of self-custody and managed custody options available today.

What Does This Mean for Hardware Wallet Security?

Hardware wallets remain the standard recommendation for long-term bitcoin storage. But this incident highlights that firmware quality determines security as much as hardware design does.

The failure here was a specific firmware implementation that silently degraded key generation without any visible indication to the user. The device still displayed seed words. It still required PIN entry. Everything looked and felt secure. But the keys it produced were reproducible.

No malware. No phishing. No user error. The device worked exactly as its firmware instructed - the firmware was wrong.

For anyone evaluating custody solutions, several layers would have limited exposure here. Multisignature setups - where a single compromised key can't move funds - are one. Unchained and other bitcoin lending platforms that use collaborative custody with multiple keyholders provide this by default. Diversifying across hardware wallet manufacturers is another. Coinbase and Anchorage Digital offer institutional-grade custody for users who prefer managed solutions.

Key management also intersects with bitcoin inheritance planning. If your estate plan relies on a single hardware wallet - especially an older device - this incident is a reminder to verify the device model and firmware version, and to consider whether multisig or a collaborative custody arrangement provides more resilience.

The companies holding bitcoin on their balance sheets - Strategy, Metaplanet, and others - use institutional custody infrastructure that wouldn't be affected by a single device firmware bug. But for individual holders, the lesson is to verify, diversify, and monitor.


This article covers a security incident. 21Rates does not endorse or recommend any specific custody solution. Always do your own research before selecting a custody method.


Sean Ristau | @SeanRistau | 21Rates / The Daily Stack

Follow @DailyStackHQ @21RatesHQ @avinmash @JodyFlournoy

388 Bitcoin companies tracked · 23 custodians · 33 Bitcoin ETFs · 19 lenders · 21 exchanges · $77B+ tracked ETF AUM · Rates verified daily