The scale of the vulnerability in Coldcard hardware wallets turned out to be far more serious than initially assumed. According to my latest analysis of blockchain data, the combined losses of users of these devices have exceeded the $115 million mark. Since July 30, attackers have drained 8,680 addresses, withdrawing a total of 1,778.58 BTC. These are not just numbers — this is a systemic failure in the security of a device that was positioned as the gold standard of protection.
All stolen coins were created after the 2021 firmware
The key detail that sheds light on the entire story: none of the affected coins were created before March 17, 2021 — that is when the vulnerable firmware version was released at block 674,951. The analysis shows that of the 6,303 bitcoins seized, none appeared before this release. The same applies to the 3,598 addresses claimed by victims: the earliest of them dates to March 22, 2021.
This time boundary is direct proof that the problem lies in key generation after the update. Devices with vulnerable firmware generated predictable keys, and bitcoins on them could only appear after that date. The average holding period of funds on the drained addresses was 1,292 days — about 3.5 years. This indicates that the attack was carefully planned: the attackers waited until victims had accumulated significant sums.
The first wave — the most devastating blow
The greatest damage came from the first wave of attacks, which brought the attackers $70.2 million — that is 61% of the total losses. The speed of the withdrawals at that time alarmed even Binance founder Changpeng Zhao (CZ). The funds were transferred across nine consecutive blocks in just 41 minutes. The operator paid a fixed fee of about 30 satoshis per vByte and drained one address per transaction.
In the first attack, 1,195 wallets were affected, and the withdrawn assets were split into four "collectors." For comparison, the Footprint E wave affected more addresses — 2,147 — and combined up to 795 vaults in a single transaction. Notably, most of the funds from the first wave remained untouched: of the 108.65 BTC, 108.57 are still in place. However, almost all of the Footprint E funds — 209.94 BTC — have already been moved, with only 4.38 BTC remaining.
Assets from the third wave moved under a different scheme: the bitcoins first went to regular wallets, but now 207.73 BTC are locked in script-based "vaults." Victim reports still lag behind what is visible on the blockchain. Only 192 people from the already published cases have reported losses, with their combined damage amounting to 714.81 BTC — that is 40.2% of all stolen bitcoins. Individual losses reach 58.97 BTC, with a median of about 1.03 BTC. Another 6,890 addresses holding 1,063.76 BTC have not yet been linked to any owner.
My comment: This situation is a stark reminder that even the most "secure" hardware wallets are not immune to firmware errors. Coldcard users who have not updated their devices since 2021 should immediately check their keys and move their funds. The incident also raises the question of the need for independent auditing of random number generation in hardware devices — the price of trust here has proven too high.