Coldcard Rushes Out Firmware Fix After Hackers Drain $130 Million From "Offline" Wallets
Coinkite has shipped emergency firmware for its Coldcard hardware wallets after a years-old randomness bug let at least a dozen attacker groups brute-force private keys and siphon roughly $130 million in Bitcoin from supposedly offline devices.

Coinkite, maker of the popular offline Coldcard Bitcoin wallet, has pushed emergency firmware updates after hackers exploited a five-year-old coding flaw to steal more than $130 million worth of Bitcoin from devices marketed as immune to remote theft.
The company released firmware versions 5.6.1 and 1.5.1Q this week, according to Decrypt, which reports the update replaces the wallet's flawed random-number generator, forces users to manually add entropy through dozens of key presses, dice rolls or coin flips, and adds new checks to catch tampered transactions before signing.
How the theft happened
The root cause traces back to a March 2021 firmware change that quietly rerouted seed-phrase generation away from Coldcard's dedicated hardware randomness chip and onto a weaker software fallback. TechCrunch reported that blockchain-monitoring firms Galaxy Research and Elliptic traced the resulting losses to at least a dozen separate hacker groups, all exploiting the same predictable seed generation to reconstruct victims' private keys without ever touching the physical devices. Coinkite has since said the flaw cut effective security from 128 bits of entropy down to as little as roughly 40 bits on its oldest model.
Because the wallets never connect to the internet, owners believed their coins were safe from exactly this kind of remote attack. CBC News detailed victims discovering their "cold storage" had been drained in minutes despite following standard security practice, including one attack wave that pulled tens of millions of dollars from more than a thousand addresses in under 41 minutes.
"None of it mattered" — a victim, describing following every recommended security step before losing funds anyway.
The theft unfolded in waves beginning in late July, with the running total climbing past $130 million by early August as more attackers piled onto the same vulnerability. Coinkite has not disclosed how many customers were affected in total.
The episode has rattled the self-custody hardware wallet industry, which sells itself on the premise that keeping keys offline defeats hackers. Competing device makers and security researchers have used the incident to push customers toward wallets with independently audited randomness sources, while Coinkite is urging every Coldcard owner still on older firmware to update immediately and migrate funds to freshly generated seed phrases rather than simply patching in place.
Coinkite says it is continuing to work with blockchain investigators to trace the stolen funds and has not ruled out further security disclosures as the forensic review continues.