SwiflTrail

The Coldcard Drain: 15 Attackers, 7,300 Wallets, and a MicroPython PRNG Failure

CryptoEagle Security

Hook.

The first anomaly is the ratio: 73 reported victims, 7,300 vulnerable wallets, $130 million in exposed Bitcoin, and 15 separate attacker clusters. Galaxy Research released those numbers while the attack was still running. Coinkite's own warning landed after the first stolen coins were already moving. That sequencing tells you everything. This is not a theory. This is an active extraction.

Fifteen attackers. That number is not static. It grows daily. Anyone who can run a key-search script can join. The barrier to entry is not exploit development skill. It is the ability to scan Bitcoin's public transaction graph and match low-entropy private keys to visible public keys. The chain stores all the evidence. Attackers just had to wait for the math to fall apart.

Hashes don't lie. Wallets do.

Context.

Coldcard built its reputation on the opposite of convenience: no Bluetooth, no camera, no touchscreen. It was the hardware wallet for people who distrusted everything, including the firmware they were running. That paranoia-first positioning made it the default choice for a specific class of Bitcoin accumulator. People did not buy Coldcards to trade memecoins. They bought them to hold a decade of savings in cold storage.

That trust model gives this incident its severity. A compromised exchange wallet is a story about operational security. A compromised hardware wallet is a story about the root of trust itself. If the machine that generates your private keys is dishonest, then every downstream safety practice becomes decoration.

Coinkite's firmware architecture is the culprit. The company did not ship a malicious backdoor. It shipped an entropy failure. Somewhere in the seed-generation path, the firmware fell back to MicroPython's software pseudo-random number generator instead of the hardware true random number generator. The result was a private key generated with dramatically less security than the Bitcoin protocol assumes.

The Coldcard Drain: 15 Attackers, 7,300 Wallets, and a MicroPython PRNG Failure

Core Evidence Chain.

Let me be specific about the numbers. On the Mark 2 and Mark 3, the effective entropy was around 40 bits. On the Mark 4, it was around 72 bits. Target entropy for a Bitcoin private key is 128 bits. The difference between 72 and 128 is not marginal. It is the difference between a vault door and a bicycle lock. 40 bits is less than the password space of a reasonably chosen 8-character password.

A 40-bit key can be brute-forced by a determined adversary with access to GPUs or specialized hardware. Bitcoin's blockchain is public. When a wallet spends from an address, the public key is exposed. An attacker can take that public key and solve the discrete logarithm problem over the weak key space. This is a known attack path for low-entropy signatures. It is not theoretical. The first thefts occurred before Coinkite's announcement. That means someone else spotted the pattern independently. There may have been multiple attackers before the public report, not after.

I have audited wallet-generation flows for years. In 2020, while tracking fragmented DeFi liquidity pools, I spent more time than I expected looking at how wallets derive keys. The security assumptions that matter are not advertised in the brochure. They are hidden in the supply chain, the hardware random number generator integration, and the fallback logic. A single line of code that routes randomness through a software PRNG undoes everything else.

Here is the uncomfortable part. Coinkite pushed a hotfix for the firmware. The hotfix is meant to stop new seeds from being generated with low entropy. It does not repair the damage already done. Every seed generated under the vulnerable firmware is permanently compromised. If you update your Coldcard today, your existing Bitcoin is still at risk. The only fix is to migrate the funds to a completely new wallet with a fresh seed generated by known-good hardware.

This is why the incident is still live. The vulnerable wallets are not patched. They are waiting. Even if no additional theft occurs from the already-scanned set, the clock is ticking. The hotfix gives future seeds a chance, but historical seeds are exposed forever. Users who do not migrate are betting that no attacker has scanned their particular address. That is a bad bet.

Galaxy Research said the number of victims could reach into the thousands. The official count is only the people who have come forward. Many Bitcoin holders are not monitoring their addresses daily. Some will not check until the next bear market. Others will check only after they try to sell and find a zero balance. The true scale of this extraction is probably already larger than the published numbers.

Contrarian Angle.

The popular framing will be that Coldcard was "hacked." That is not quite right. A hack implies an external actor breaking in. This is a failure of random number generation inside the device. It is more like discovering that a bank vault has been leaving the combination on a sticky note for years. The thief did not pick the lock. The lock was never locked.

Even more dangerous is the "update your firmware" message. It sounds like a responsible security response. But it also creates a false sense of closure. Updating the firmware prevents future damage. It does not heal past exposure. Every Coldcard user who assumes the hotfix makes their existing wallet safe is now walking around with a compromised private key and a placebo. The only correct response is not "update." It is "migrate."

The on-chain behavior of the attackers contradicts the narrative of panicked criminals. Roughly 90 percent of the stolen Bitcoin has not moved. That is not an accident. Attackers are not simply dumping. They are sitting on the largest part of the haul. This suggests coordination, patience, or a wait for liquidity conditions that allow for lower slippage. It also suggests that some of these attackers may be doing strategic, slow extraction rather than immediate liquidation.

The Coldcard Drain: 15 Attackers, 7,300 Wallets, and a MicroPython PRNG Failure

Follow the liquidity, not the narrative.

The fact that stolen funds remain dormant also means the market impact has been muted. $130 million is large for a theft but small relative to Bitcoin's global daily volume. The price impact is secondary. The primary damage is to the self-custody trust model. If a hardware wallet fails at the one thing it exists to do, the entire sector suffers. Users do not need a 51 percent attack to lose faith. They just need to hear that a famous device shipped with 40 bits of entropy.

Fragmented yields, fragmented trust. The same principle applies to hardware wallets: when the foundation is split into weak components, the whole structure fails.

Takeaway.

Monitor the tagged attacker addresses. If large batches of the stolen Bitcoin start moving, expect exchange alerts and possibly enforcement action. For Coldcard owners: do not update and then go back to sleep. The update is for the future. Your past is compromised. Move your coins to a new wallet, generated on different hardware, preferably one whose randomness source has been independently audited.

The broader lesson is simple. Security claims are not facts. They are code paths, hardware assumptions, and fallback behaviors. The Bitcoin blockchain records everything. It knows which wallets were created with weak entropy, even if the owner does not. The next wave of attackers will not announce themselves. They will simply scan, solve, and sign.

On-chain truth > Twitter narrative. The damage is already on the ledger. The only remaining question is whether you are reading it in time.

Market Prices

Coin Price 24h
BTC Bitcoin
$64,935.5 +1.17%
ETH Ethereum
$1,919.31 +2.44%
SOL Solana
$74.38 +0.35%
BNB BNB Chain
$599 +0.96%
XRP XRP Ledger
$1.07 -0.53%
DOGE Dogecoin
$0.0703 +0.10%
ADA Cardano
$0.1902 -1.50%
AVAX Avalanche
$6.69 -0.36%
DOT Polkadot
$0.8487 +0.35%
LINK Chainlink
$8.2 +0.21%

Fear & Greed

27

Fear

Market Sentiment

Event Calendar

{{年份}}
28
03
unlock Arbitrum Token Unlock

92 million ARB released

12
05
halving BCH Halving

Block reward halving event

08
04
upgrade Solana Firedancer

Independent validator client goes live on mainnet

10
05
upgrade Ethereum Pectra Upgrade

Raises validator limit and account abstraction

15
04
halving Bitcoin Halving

Block reward reduced to 3.125 BTC

18
03
unlock Sui Token Unlock

Team and early investor shares released

22
03
unlock Optimism Unlock

Circulating supply increases by about 2%

30
04
upgrade Celestia Mainnet Upgrade

Improves data availability sampling efficiency

Tools

All →

Altseason Index

43

Bitcoin Season

BTC Dominance Altseason

Gas Tracker

Ethereum 28 Gwei
BNB Chain 3 Gwei
Polygon 42 Gwei
Arbitrum 0.5 Gwei
Optimism 0.3 Gwei

Market Cap

All →
# Coin Price
1
Bitcoin BTC
$64,935.5
1
Ethereum ETH
$1,919.31
1
Solana SOL
$74.38
1
BNB Chain BNB
$599
1
XRP Ledger XRP
$1.07
1
Dogecoin DOGE
$0.0703
1
Cardano ADA
$0.1902
1
Avalanche AVAX
$6.69
1
Polkadot DOT
$0.8487
1
Chainlink LINK
$8.2

🐋 Whale Tracker

🟢
0x1c37...cf2b
1h ago
In
9,311,064 DOGE
🔵
0x7939...f86c
1d ago
Stake
4,992,954 USDT
🟢
0x6a58...d558
1d ago
In
1,796.95 BTC

💡 Smart Money

0xc90b...56f7
Early Investor
+$5.0M
73%
0xe5b9...ec5d
Arbitrage Bot
-$3.2M
75%
0x10ba...d7c4
Arbitrage Bot
+$4.4M
78%