

Hardware wallets have long been celebrated as the gold standard of cryptocurrency security, anchored by the famous industry adage: "Not your keys, not your coins." However, an escalating security nightmare surrounding Coldcard Bitcoin wallets has shaken that fundamental belief to its core.
According to updated tracking from Galaxy Research, total observed stolen funds have now reached approximately 1,367 BTC—worth roughly $88.6 million—spread across 4,585 compromised wallet addresses. With attackers continuing to systematically drain vulnerable devices, crypto security experts are warning that every single-signature wallet affected by the underlying vulnerability will eventually be emptied unless users act immediately.
The source of this devastating exploit dates back to a March 2021 firmware build error by Coinkite, the manufacturer of Coldcard hardware wallets.
During key generation, a cryptographically secure hardware device relies on high-quality entropy (pure randomness) to generate a seed phrase. The 2021 firmware glitch severely compromised this process, resulting in seed phrases created with vastly insufficient randomness. Because the entropy pool was constrained, the resulting private keys became predictable and computationally guessable by sophisticated threat actors.
For years, millions of pounds in Bitcoin sat undisturbed on these addresses. But once attackers calculated the compromised key spaces, those dormant funds became easy targets.
Galaxy Research’s head of research, Alex Thorn, revealed that the thefts have unfolded in three distinct waves. The third and most recent wave alone swept away 207.73 BTC.
Key insights from the ongoing investigation include:
The vulnerability has led to tragic financial losses for individual investors who believed they were following every recommended security protocol.
Canadian coach Jonathan Goodman shared his personal ordeal after losing 18.25 BTC (approximately $1.6 million CAD) in a span of just seven minutes. Despite keeping his recovery seed phrases stored safely inside an offline physical safety deposit box that had never touched the internet, his funds were swept remotely due to the predictable nature of his keys.
"Perhaps the hardest part about this is that I did everything right," Goodman noted, describing the helplessness experienced by victims of hardware-level cryptographic failures.
This disaster has sparked an unprecedented reversal in user behaviour across the crypto community. In a stark inversion of the self-custody movement, panicked holders are rushing to transfer their Bitcoin off single-signature hardware wallets and back onto centralised exchanges like Coinbase and Binance, or onto newly generated, verified secure devices.
For many, temporary custodian holding on an exchange has suddenly felt safer than managing a hardware wallet generated during the flawed firmware window.
If you generated a single-signature Bitcoin wallet on a Coldcard device using firmware updated around or after March 2021, take the following steps immediately:
For More Information:
To read the original reporting and stay updated on further developments regarding this exploit, visit the source article on Decrypt:
👉 Coldcard Bitcoin Exploit Balloons to $88 Million as Attackers Keep Draining Wallets
Disclaimer: This article is provided for informational purposes only, mistakes may be made, and it's not offered or intended to be used as legal, tax, investment, financial, or any other advice.
