A flaw in a hardware wallet’s random number generation system transformed supposedly “unbreakable” seed phrases into predictable ones, leading to a Bitcoin theft worth roughly $38 million.
Around 594 BTC, valued at approximately $38 million, was removed from nearly 500 different wallets between 01:31 and 01:56 UTC on Friday. The attack was traced to a weakness in the way Coldcard hardware wallets generated private keys.
The stolen Bitcoin was moved through 1,324 separate transfers across 500 transactions within a span of just three blocks. After the initial movement, about 562 BTC was merged into a single address, where the funds have remained inactive.
Each compromised wallet was a single-signature wallet containing more than 0.15 BTC. Many of the wallets had not been used for years, and the affected funds dated back to transactions made between 2021 and 2026, closely aligning with the period when the vulnerability was present.
Coldcard is an offline Bitcoin hardware wallet created by Canadian company Coinkite. The device stores private keys away from internet-connected systems, with product generations including Mk2, Mk3, Mk4, Q, and Mk5 released over several years.
The vulnerability was tied to the firmware version installed when a wallet was originally generated, not when the physical hardware device was purchased.
Bitcoin wallet seeds are designed to rely on highly secure randomness, creating a massive number of possible combinations that makes guessing a seed virtually impossible.
However, Coldcard’s firmware introduced a weakness that reduced this security. Research from Block’s Bitcoin engineering and security teams found that a build configuration prevented the device from using its dedicated hardware random number generator. A supporting library only checked whether the setting was present, rather than confirming that it was activated.
This caused the wallet to silently fall back on a basic software-based random generator that relied on the device’s serial number and clock registers to create keys.
Those values were not confidential. The serial number is fixed manufacturing data, while clock information is a measurable state that attackers could potentially narrow down or replicate using similar hardware. Block traced the issue back to a code update from March 1, 2021, which was included in firmware version 4.0.0 released that month.
Coinkite warned affected users who generated seeds on Mk3 devices running version 4.0.1 or later and stated that its initial review suggested Mk4, Q, and Mk5 devices were not impacted.
Block said it informed Coinkite about the vulnerability, and the company confirmed receiving the findings. Both teams described their reviews as ongoing, while Block explained that it published the details before completing full exploit verification because the attack was already happening.
The issue affected more than seed phrase generation. The same flawed randomness process was also used for Coldcard paper wallet private keys, where the generated value directly serves as the key, as well as seed-splitting masks, device cloning keys, and Key Teleport functionality.
Despite the significant Bitcoin loss, the broader market showed limited reaction. Bitcoin remained above $64,000 during early Asian trading, suggesting the incident had little immediate impact on overall market sentiment.

































