Overview
- Blockchain analysts traced rapid coordinated sweeps that began on July 30 and emptied thousands of single-signature Coldcard addresses without touching victims’ devices.
- A March 2021 firmware change caused the wallet to fall back to a software pseudo-random number generator during seed creation, collapsing expected entropy and making seeds enumerable.
- Coinkite released emergency firmware, destroyed vulnerable inventory, and told customers that any seed generated on affected builds is irreparably weak and must be replaced and migrated.
- Galaxy Research has confirmed 1,596 BTC stolen across thousands of addresses and warned totals could rise to about 2,055 BTC if a suspected fourth wave is validated, while investigators have shared clustered attacker wallets with law enforcement and exchanges and say most stolen coins remain unmoved.
- The exploit has pushed many users to move funds, distorted on-chain metrics for small transfers, and renewed debate over self-custody versus custodial or multi-signature custody options for protecting long-term holdings.