An attacker exploited a flaw in how some Coldcard hardware wallets generated keys to steal roughly 594 bitcoin, worth about $38 million, from around 500 single-signature wallets in under 30 minutes.
Roughly 594 bitcoin was swept out of around 500 separate wallets between 01:31 and 01:56 UTC on Friday. The theft moved 1,324 chunks of bitcoin across 500 transactions inside a three-block window, with 562 BTC then consolidated into a single address that has not moved. Every drained wallet was single-signature and each held more than 0.15 BTC. Many had been dormant for years, and the coins spanned 2021 to 2026, matching the flaw's age almost exactly.
Coldcard is a hardware wallet built by Canadian firm Coinkite, a small standalone device that stores bitcoin keys offline, away from internet-connected computers. Mk2, Mk3, Mk4, Q and Mk5 are successive generations of that product. Exposure depends on the firmware the device was running at the moment the wallet was first created, not on when the hardware was bought.
How the flaw worked
A wallet's seed, the secret phrase controlling the funds, is meant to be drawn at random from a pool so vast that guessing is hopeless. Coldcard's firmware was not doing that. According to a report published by Block's Bitcoin engineering and security teams, a build setting told the device to skip its own hardware randomness generator, and a check in a supporting library tested only whether that setting existed rather than whether it was switched on.
Key generation quietly fell through to a basic software substitute seeded from the chip's serial number and clock registers. None of those are secrets: the serial number is fixed factory metadata, and the clock values are timing state an attacker can narrow down or measure on a device of their own. Block traced the change to a commit dated March 1, 2021, shipped in firmware 4.0.0 that month.



