Galaxy Digital researchers say a Coldcard firmware flaw may have exposed Bitcoin holders to a brutal lesson in entropy: if the seed is weak, the wallet is already half-broken. The firm estimates roughly $70 million was drained, while Coinkite says it has fixed the bug and taken responsibility for affected devices.
- Galaxy Digital says about $70 million was stolen.
- The issue involved a Coldcard firmware bug tied to seed generation.
- Coinkite has acknowledged the flaw and released emergency fixes.
- Updating firmware alone does not secure existing seeds.
This was not a typical exchange meltdown or some clown-show custodial fail. It was a self-custody failure in one of the exact places Bitcoin users are told to trust most: the generation of the secret recovery phrase, or seed, that creates a wallet’s private keys.
In plain English, the device was supposed to create a highly unpredictable seed using hardware-based randomness. Instead, Galaxy’s analysis says a firmware bug weakened that randomness, making some affected recovery phrases more predictable than they should ever be. For Bitcoin security, that is not a small hiccup. That is the foundation cracking.
Galaxy Digital researchers say the theft unfolded fast. Their analysis says the full event spans six blocks and 41 minutes, and that the vast majority of funds were swept in under an hour. They also noted that three intervening blocks contain no sweep activity at all, which suggests the transactions were broadcast in batches rather than continuously.
That is useful because it shows the drain was not a random scrape. It looks organized, deliberate, and timed. Onchain, it is the kind of pattern that says someone knew exactly what they were doing.
Galaxy also says the loss profile was concentrated in ordinary self-custody holdings. In its words:
“The loss profile is dominated by sub-1 BTC addresses in count, but by 1-50 BTC addresses in value. This is the shape of individual self-custody, not institutional or exchange holdings.”
That distinction matters. This was not the failure of a giant exchange treasury stack with teams of operators and layered controls. It points to individual holders, the people who buy hardware wallets specifically to avoid the risks of centralized custody.
Coinkite, the company behind Coldcard, says it takes full accountability for the firmware bug and has apologized to affected users. It also released emergency firmware updates for affected models:
- Mk3: 4.2.0 or later
- Mk4 and Mk5: 5.6.0 or later
- Coldcard Q: 1.5.0Q or later
Coinkite says the updates remove the vulnerable software fallback path and ensure new seeds use the intended hardware true random number generator. That is the correct fix going forward, but it does not repair a seed that was already created on vulnerable firmware.
That is the part users absolutely need to understand: a firmware update alone does not make an old weak seed safe. If the recovery phrase was generated on affected firmware, the old key material remains the weak link.
The practical response is blunt: generate an entirely new recovery phrase on fixed firmware, then move the BTC to fresh addresses derived from that new seed. Updating the device and carrying on with the same seed is security theater with a shiny screen.
For readers less familiar with the mechanics, a seed or secret recovery phrase is the set of words that can recreate a wallet and its private keys. If the seed is predictable enough, an attacker may be able to derive the keys and steal the funds. That is the entire castle, not just the front door.
Coinkite says affected Mk4, Mk5, and Q seeds had about 72 bits of entropy rather than the expected 128 bits. Entropy means unpredictability. Less of it means fewer possible seed combinations, which makes attacks more feasible than they should be for a hardware wallet.
That does not mean every affected seed was instantly crackable by random opportunists. But it does mean the security margin was slashed hard enough to matter, and in Bitcoin security, a reduced margin is exactly how ugly surprises happen.
There is also an important source-of-truth distinction here. Galaxy Digital is providing the forensic estimate of the theft and the onchain analysis. Coinkite is the vendor acknowledging the bug and issuing the remediation. Those are related, but they are not the same thing. One is the device failure; the other is the loss estimate and observed drain pattern.
That matters because Galaxy itself says its analysis may not be complete. So while the estimated losses are large, and ugly, the cleanest way to frame them is as Galaxy’s best current estimate, not some immutable final number handed down by the gods of cryptography.
There is also a broader lesson here for the “just use a hardware wallet” crowd. Hardware wallets are still a strong tool, and they reduce attack surface compared with software wallets or exchange custody. But they are only as good as their weakest security assumption, and here that weak point was seed generation itself.
Bitcoin gives users sovereignty. It also gives them full responsibility. That tradeoff is the whole point, but it is unforgiving. If the seed is bad, there is no support ticket, no rollback, no customer service rep with a magic wand.
Onchain analysis is powerful, but it has limits. It can show funds moving, wallet patterns, and sweep behavior. It cannot, by itself, identify the attacker or prove intent. The blockchain is a ledger, not a confession booth.
The clean takeaway for affected users is simple:
- Update to the fixed firmware.
- Generate a completely new seed on the corrected device.
- Move all BTC to fresh addresses from that new seed.
Anything less leaves the old seed in play, and that is the problem.
Key questions and takeaways
-
What went wrong with Coldcard?
Galaxy Digital says a firmware bug weakened the randomness used in seed generation, making some recovery phrases less secure than intended. Coinkite says it fixed the issue and removed the vulnerable fallback path. For more background, see Coinkite’s warning on seed generation and its technical deep dive into the entropy issue. -
Did the firmware update fix old wallets?
No. Coinkite says updating firmware does not repair an existing seed. Users with affected seeds need to create a new one and move their funds. In practical terms, that means old recovery phrases tied to vulnerable firmware are still sitting there like a loaded foot-gun. -
How much was stolen?
Galaxy Digital estimates roughly $70 million was drained. That figure should be treated as Galaxy’s current estimate, not a universal final count. Other reports put the theft at about $70.2 million drained from Bitcoin, while separate coverage later pegged a Coldcard wallet flaw at a lower loss total depending on the cutoff used. -
How fast did the drain happen?
Galaxy says the full event spans six blocks and 41 minutes, with most of the funds swept in under an hour. -
Who was most affected?
Galaxy says the loss profile reflects individual self-custody more than institutional holdings. In other words, this looks like retail Bitcoin users getting hit, not a giant exchange vault. -
Can an old weak seed be made safe with an update?
No. A patched wallet does not rewrite old key material. If the seed was generated on vulnerable firmware, the only real fix is a new seed and a full migration of funds. Coinkite’s guidance is consistent with its BIP-85 documentation, which explains deterministic entropy export for advanced seed workflows.
Coldcard’s reputation will take a serious hit from this, even if the flaw was limited to specific firmware versions. A hardware wallet is supposed to be the last place randomness fails. When that happens, the damage is immediate, public, and expensive.
There is no sugarcoating the optics here: a device built for sovereign custody stumbled on the one job it absolutely cannot fuck up. That said, the broader hardware-wallet model is still worth defending when it works properly, and Coldcard MK5 remains part of the ongoing push for bitcoin-only security hardware. The lesson is not to abandon self-custody; it is to stop treating any device as magically trustworthy just because it has a metal case and a premium price tag.
Meanwhile, larger Bitcoin finance plumbing keeps advancing in the background. As firms like Galaxy keep building institutional rails, including Bitcoin-backed loans, the market is still straddling two worlds: hardened self-custody for individuals and increasingly polished financial products for the suits. And on the policy side, the fight over market structure remains a mess, with Galaxy Digital cutting CLARITY Act odds as the Senate clock runs down.
None of that changes the blunt reality for anyone affected by this mess: if the seed was poisoned at birth, the wallet was never truly safe.
Further reading
One more angle on the Coldcard seed mess, for anyone tracking how deep the damage may run.