How Bitcoin Cold Wallets Lost $70 Million in an Attack That Never Touched the Devices
Over $70 million in bitcoin was stolen from nearly 1,200 Coldcard hardware wallets due to a firmware flaw that allowed attackers to recreate private keys offline. The attack did not require physical access to the devices.
Intelligence analysis by Gemini 2.5 Flash Lite

A sophisticated attack exploited a firmware vulnerability in certain Coldcard hardware wallets, enabling attackers to reconstruct private keys offline by guessing predictable seed phrases. This allowed them to steal over 1,000 BTC, valued at $70 million, without ever physically interacting with the compromised devices, raising significant concerns about the security of cold storage.
Imagine your bitcoin is like treasure in a locked box, and the key is hidden in a super-secret code. Normally, the box-making machine makes the code so complicated that nobody can guess it. But this machine had a glitch, and it made codes that were easier to guess. Someone with a powerful computer guessed these easier codes, found the keys, and took the treasure without ever touching your locked box.
Analysis
A New Frontier in Offline Exploitation
The recent theft of over $70 million in bitcoin from Coldcard hardware wallets represents a significant escalation in the sophistication of cryptocurrency attacks. Unlike traditional exploits that target online exchanges or rely on phishing to gain access to private keys, this attack bypassed physical security entirely. The core of the exploit lies in a flaw within Coldcard's firmware, specifically how it generated seed phrases. Instead of relying on a truly random hardware generator, a misconfiguration caused the devices to fall back to a less secure software-based method, seeded by predictable factors like the device's serial number and clock registers. This drastically reduced the number of possible private keys an attacker would need to test, transforming an astronomically improbable task into a computationally feasible one.
The Mechanics of Enumeration
Researchers from Galaxy Research detailed how the attacker was able to systematically enumerate likely private keys. By generating candidate seeds on their own hardware and deriving the corresponding addresses, the attacker could then cross-reference these addresses against the public blockchain. This process, running entirely on the attacker's machines, required no interaction with the victim's hardware wallet. The fact that the stolen funds were spread across nearly 1,200 wallets, using different address formats, strongly suggests a systematic, automated approach rather than a targeted attack on specific individuals. This indicates a broad vulnerability that could potentially affect a large number of users who generated their seeds on the affected firmware versions.
The Unseen Threat and Future Implications
A particularly alarming aspect of this exploit is the inability for users to definitively determine if their wallets are compromised. Coinkite, the maker of Coldcard, has identified affected models, but until a verifiable solution is implemented, users who generated seeds on potentially vulnerable firmware must operate under the assumption that their funds are at risk. The attacker's use of a blockchain data provider's services to track the stolen funds, while providing a lead for investigators, also underscores the evolving tactics employed by malicious actors. This incident serves as a stark reminder that the security of digital assets relies on a multi-layered approach, and even the most trusted cold storage solutions are not immune to novel forms of attack.
Key points
- Over $70 million in bitcoin was stolen from 1,196 Coldcard hardware wallets due to a firmware vulnerability.
- The attack allowed attackers to recreate private keys offline by exploiting predictable seed generation, without touching the devices.
- The vulnerability affected specific Coldcard models, reducing the complexity of private key generation from astronomical to countable.
- Users cannot easily determine if their wallets are vulnerable, creating ongoing risk.
- Investigators are tracing the attacker through logs from a blockchain data provider.
The swift identification of the vulnerability and the ongoing investigation by security firms and authorities offer hope for recovering the stolen funds and preventing future attacks. This incident may spur hardware wallet manufacturers to implement more robust security audits and firmware updates, ultimately strengthening the overall security of cold storage solutions.
The inability for users to verify if their seed phrases were generated on vulnerable firmware creates a persistent risk, potentially leading to further losses if the attacker continues their campaign. This could significantly undermine user confidence in hardware wallets, pushing individuals towards less secure storage methods.



