Overview
- Researchers have confirmed roughly 1,596 bitcoin were stolen from thousands of Coldcard-derived addresses, with Galaxy Research saying the losses come from multiple scripted sweep waves and at least 15 distinct attacker clusters.
- The root cause was a March 2021 firmware build that bypassed the device’s hardware random-number generator and fell back to a deterministic MicroPython routine, cutting seed entropy from the expected 128 bits to much lower effective strengths.
- Attack activity began in the last days of July, with large, rapid sweeps reported on July 29–30 that emptied vulnerable addresses while about 90% of stolen coins have not moved and are flagged with exchanges and law enforcement.
- Coinkite issued emergency firmware updates, destroyed remaining vulnerable inventory, and urged all users who created seeds on the flawed builds to generate new seeds on patched firmware and transfer funds because updates cannot secure already‑generated weak seeds.
- The exploit has pushed users to migrate funds, raised exchange inflows and phishing risks during migrations, and triggered broad, AI-assisted community audits and renewed debate over multisig, third‑party custody, and formal RNG verification standards.