Major bitcoin wallet flaw drains 594 BTC in 25-minute sweep

A critical firmware flaw in Coldcard hardware wallets allowed attackers to predict private keys by bypassing the device's hardware random number generator. This vulnerability, which affected specific models since 2021, resulted in the theft of 594 BTC from dormant, single-signature wallets.
Why it matters
This incident highlights a major security failure in self-custody hardware, demonstrating how a single software misconfiguration can compromise assets previously considered immune to online threats.
The theft moved 1,324 chunks of bitcoin across 500 transactions inside a three-block window, with 562 BTC then consolidated into a single address that has not moved.
Every drained wallet was single-signature and each held more than 0.15 BTC. Many had been dormant for years and the coins spanned 2021 to 2026, matching the flaw's age almost exactly.
Coldcard is a hardware wallet built by Canadian firm Coinkite, a small standalone device that stores bitcoin keys offline, away from internet-connected computers. Mk2, Mk3, Mk4, Q and Mk5 are successive generations of that product, released over several years the way a phone maker ships numbered models.
Exposure depends on the firmware the device was running at the moment the wallet was first created, not on when the hardware was bought.
Get smarter about the news
Sign up free for a feed built around what you actually care about, Dive Deeper research on any story, and the full text of every article.
Create free accountAlready have an account? Sign in