An ongoing exploit targeting Coldcard hardware wallets has drained at least 1,816 BTC, worth roughly $114 million, from more than 5,200 addresses since attacks began on July 30, according to CoinDesk. Rather than a single breach, the losses have climbed in waves over the past week as researchers and the wallet's manufacturer worked to identify and patch the underlying flaw.

The root cause traces back further than the current attack wave. Security researchers found the vulnerability originated in a March 2021 firmware build for Coldcard Mk3 devices running versions 4.0.1 through 4.1.9, where a bug routed wallet seed generation through a software random number generator instead of the device's dedicated hardware RNG, weakening the randomness underpinning affected users' private keys. Coinkite, the Canadian manufacturer behind Coldcard, released patched firmware within roughly two days of the first reported losses and said it destroyed its remaining inventory of devices carrying the vulnerable build, while confirming its TAPSIGNER, OPENDIME and SATSCARD products were unaffected.

a person holding a cell phone in their pocket
Photo by Vagaro on Unsplash

Wall Street sees a silver lining

For at least two Wall Street research desks, the fallout looks less like a warning sign for bitcoin broadly and more like a tailwind for regulated products built around it. Cantor Fitzgerald called the episode a "positive read-through for crypto-related equities."

"The read-through is second-order but we would expect that token flows to custodians and exchanges will increase following the hack," said Cantor analyst Nico Pasquariello.

Cantor named Robinhood Markets, Coinbase Global, BitGo Holdings, Bullish, eToro Group and Gemini Space Station as likely beneficiaries of investors moving assets away from self-custody and toward custodied or exchange-held positions. FRNT Financial offered a similar read but with more sympathy for the affected users.

"The reaction within the BTC community to the exploit was one of heartbreak," FRNT said, noting that many victims believed they had followed security best practices.

FRNT said it expects hardware wallet makers to respond by hardening their security rather than triggering a wholesale retreat from self-custody, but also pointed to spot bitcoin ETFs as a natural landing spot for risk-averse holders looking to sidestep hardware-level risk altogether.

Not the first entropy failure

The Coldcard incident revives a narrower but recurring category of bitcoin theft: flawed randomness in key generation, rather than a stolen password or phishing attack. A comparable case emerged in 2023 with the so-called "Milk Sad" vulnerability, in which weak entropy in certain wallet-generation libraries let attackers predict private keys and drain around $900,000 from affected wallets. Blockchain analytics firm Galaxy Research, which has been tracing the stolen Coldcard funds on behalf of dozens of victims, has said roughly 90% of the stolen coins remain unmoved, leaving open the possibility of at least partial recovery if the funds can be frozen before being laundered through exchanges or mixers.