Coldcard Security Breach Triggers Massive Bitcoin Migration After $88.6 Million Theft
A critical firmware flaw in the air-gapped hardware wallet led to the largest movement of small-value Bitcoin since the FTX collapse.
A critical security vulnerability in Coldcard hardware wallets has triggered a massive migration of Bitcoin as users scramble to secure their assets. The breach, which allowed attackers to reproduce seed phrases and drain funds, has shaken confidence in one of the industry's most respected air-gapped security solutions.
Total losses from the attack reached approximately $88.6 million, equivalent to roughly 1,367 BTC. The breach began with a rapid sweep of funds; while initial reports cited 594 BTC stolen in 25 minutes, later analysis by Galaxy Research revealed that 1,082.65 BTC were actually drained from 1,196 addresses within a 41-minute window. In the aftermath, CryptoQuant reported that 39,600 BTC were moved in small, sub-1 BTC transactions as users rushed to migrate their holdings to new addresses. This represents the largest movement of small-value transactions since the collapse of FTX.
The Vulnerability
The breach stemmed from a flaw in the entropy generation process used to create seed phrases. The vulnerability affected a wide range of devices: Mk2 and Mk3 models running versions 4.0.0 through 4.1.9, Mk4 and Mk5 models on all versions prior to 5.6.0, and Coldcard Q devices on all versions before 1.5.0Q.
Attackers specifically targeted wallets that relied solely on device-generated seeds. According to Coinkite, the manufacturer, wallets that utilized user-generated dice rolls, multi-signature setups, or BIP-39 passphrases were not vulnerable. Coinkite explicitly stated that "affected seeds used with a BIP-39 passphrase face minimal risk."
Industry Implications
This event underscores the inherent risks of relying on automated device entropy for seed generation. For years, Coldcard has been viewed as a "gold standard" for security due to its air-gapped nature, but this breach proves that software flaws can bypass physical isolation. The scale of the subsequent fund migration demonstrates a widespread panic and a fundamental shift in user behavior, as holders realize that even high-end hardware is not immune to systemic failure.
What's Next
Users of affected Coldcard devices are urged to update their firmware immediately and move funds to new, secure addresses. While Coinkite has released fixed firmware to patch the flaw, the industry is now closely examining the role of advanced tools in discovering such vulnerabilities. Coinkite founder NVK noted that AI was likely involved in the discovery of the security flaw, suggesting a new era of automated vulnerability research that could put other hardware wallets at risk.