A vulnerability in Coldcard hardware wallets may have enabled attackers to steal over $100 million in bitcoin, according to a new report. Galaxy Research said it has high confidence that 1,596 bitcoin, worth more than $100 million, was taken from about 7,300 addresses in a series of attacks. The firm's head of research, Alex Thorn, estimated that at least 15 different attackers exploited the flaw, none of whom required physical access to the devices.
The issue lies not in the wallet itself but in how the seed phrase—the secret password protecting users' coins—was generated. A configuration error caused the wallet to use a simpler software-based random number generator instead of the dedicated hardware generator, reducing the entropy of the seeds. This made it possible for attackers to guess the seeds and drain wallets remotely.
One affected user, Toronto entrepreneur Jonathan Goodman, reported losing 18.25 bitcoin, worth over $1.17 million at the time. Despite following best practices—keeping his Coldcard offline and storing his seed phrase in a separate safe deposit box—all his wallets were emptied on July 29. “Perhaps the hardest part about this is that I did everything right,” he wrote on X.
The bug was introduced during a major software update in 2021. Coinkite, the maker of Coldcard, released firmware version 4.0.0 in March 2021, which included new code from a library called libngu. Bitcoin developer James O’Beirne identified the account “switck” as belonging to Coinkite co-founder Peter Gray, based on matching cryptographic signatures. O’Beirne said he raised concerns about the randomness process in May 2025 but was dismissed.
Block's Bitcoin engineering and security team analyzed the flawhol and found that the error occurred when two pieces of software communicated to read a setting. The setting was meant to disable one random number source after another was added, but libngu only checked whether the setting existed, not whether it was on or off. As a result, affected Mk2 and Mk3 devices received no secure randomness, while newer models like Mk4, Q, and Mk5 received only a small share, resulting in seeds with about 72 bits of randomness instead of the intended 128.
Coinkite has not responded to the identity claim or the vulnerability report. The company's public source code was meant to embody the crypto ethos of “don't trust, verify,” but users did not inspect it closely enough. The incident highlights that even air-gapped systems are not a perfect fix, as security must begin with key generation and continue through the entire custody process.







