One of the largest self-custody failures in Bitcoin's history has been traced to a firmware bug that sat undetected for half a decade. Whale Insider reported that a Coldcard hardware wallet flaw caused 1,816 BTC, worth roughly $116 million, to be stolen, a theft that is reviving questions about how much trust self-custody hardware actually deserves.
A Five-Year-Old Flaw
According to research published by TRM Labs, the vulnerability had been present in Coldcard firmware version 4.0.0 since March 2021. Under specific conditions, the device bypassed its dedicated hardware randomness chip during key generation and fell back to a predictable software substitute instead, meaning any seed phrase generated on an affected device was never as random as users assumed.
Four Waves of Draining
The theft wasn't a single event. TRM Labs' analysis shows an attacker began moving funds on July 30 and executed the drain in four separate waves, ultimately pulling roughly 1,816 BTC out of more than 5,200 addresses that had been generated on Coldcard devices during the affected window. The scale and staggered execution suggest the attacker had mapped out a large set of vulnerable addresses well before starting to withdraw, rather than discovering and exploiting them in real time.
Related: Term Labs Loses $8.5M in Governance-Vulnerability Exploit
What Coldcard Users Should Do
Coldcard maker Coinkite has urged anyone who generated a seed on the device between March 2021 and the firmware patch to treat that seed as compromised and migrate funds to a newly generated wallet immediately. Coinkite CEO Rodolfo Novak has suggested AI-assisted code analysis may be behind the bug's discovery, though independent security researchers point instead to a straightforward engineering error in how the randomness fallback was implemented. Either way, the incident is a reminder that hardware wallets are not a substitute for verifying a device's security track record, and that firmware bugs can sit dormant for years before anyone, attacker or defender, finds them.