Block’s engineering team has identified the entity believed to be behind a major exploit involving COLDCARD hardware wallets, tracing the attacker’s activity to a blockchain services provider connected to the theft.
The security breach occurred on July 30 and resulted in the loss of approximately 594 Bitcoin from nearly 500 wallets. The stolen cryptocurrency was valued at about $38 million at the time of the incident. The attacker reportedly emptied the affected wallets within roughly 25 minutes, with the transactions taking place between 01:31 and 01:56 UTC.
Investigators determined that the exploit was linked to a firmware vulnerability introduced more than five years earlier. The issue originated in version 4.0.0 of the COLDCARD firmware, which was released in March 2021.
The compromised firmware disabled the hardware random number generator and replaced it with a predictable software-based process, potentially allowing attackers to reproduce wallet seeds generated on affected devices.
The vulnerability primarily affected COLDCARD Mk3 devices and a limited number of Mk2 units. The risk applied to wallets whose recovery seeds had been created while the affected firmware version was installed.
Hardware random number generators are designed to produce unpredictable values that help secure cryptographic keys and wallet recovery phrases. According to the technical findings, the affected firmware relied instead on a software fallback that used non-secret seed inputs. An attacker who understood the weakness could potentially reconstruct wallet seeds by using device-specific metadata and other predictable information.
Evidence Suggests Years of Preparation
The investigation indicated that the attacker may have known about the vulnerability for several years before carrying out the theft. The accounts selected during the incident appeared to include dormant wallets, suggesting that the attacker may have spent considerable time identifying vulnerable devices and calculating the associated wallet seeds.
The short duration of the attack also pointed to substantial preparation. Engineers assessed that the attacker may have generated vulnerable wallet seeds in advance and developed automated tools to execute the withdrawals rapidly.
The speed and scale of the operation suggested that the attacker had likely pre-computed the targeted wallet credentials and automated the process used to transfer the Bitcoin.
Block worked with Coinkite, the manufacturer of COLDCARD hardware wallets, to investigate the incident and trace the movement of the stolen funds. Their analysis reportedly connected the attacker’s on-chain activity to a blockchain services provider.
The joint investigation supported an urgent disclosure process before detailed technical information about the vulnerability was released publicly. The coordinated response was intended to reduce the risk of additional exploitation while affected users were notified.
Coinkite Advises Immediate Wallet Migration
Coinkite issued an advisory for users of COLDCARD Mk3 devices and older models whose wallet seeds may have been generated under the affected firmware versions. The company’s initial assessment indicated that newer devices, including the Mk4, Q, and Mk5 models, were not exposed to the same random number generation weakness.
🚨URGENT COLDCARD SECURITY UPDATE
Read carefully before acting.
👉Mk3 seed generated on 4.0.1+ without ≥50 private, independent dice rolls: begin a careful migration now.
👉Mk4/Mk5 <5.6.0 or Q <1.5.0Q: update first, generate a new seed, then migrate.https://t.co/HshUxevCl3 https://t.co/zrkUuACRyE
— COLDCARD (@COLDCARDwallet) July 31, 2026
Users potentially affected by the vulnerability were advised to create completely new wallet seeds using unaffected hardware and transfer their cryptocurrency holdings to the newly generated wallets as soon as possible.
The recommended security measure was to abandon potentially exposed recovery seeds, generate new seeds on unaffected devices, and immediately migrate all funds to newly secured wallets.
The incident occurred while Bitcoin was trading above $64,000, although the theft appeared to have limited immediate impact on the broader cryptocurrency market.
The case highlighted the long-term security risks associated with firmware flaws in hardware wallets. Users who installed the March 2021 update may have believed that they were strengthening their device security, but some instead generated wallet seeds through a weakened and predictable random number process.
The breach also demonstrated that vulnerabilities can remain dormant for years before being exploited, particularly when attackers have sufficient time to identify affected wallets, reconstruct sensitive credentials, and automate large-scale transactions.
