COLDCARD’s seed-generation bug has turned into a full-on on-chain manhunt, with Galaxy Research tracking one suspected attacker cluster still holding 1, 159 BTC across seven addresses while another has started pushing coins through a mixer to obscure the trail.
- Firmware flaw, not a Bitcoin protocol break
- Largest known cluster still sitting on 1, 159 BTC
- Separate funds have started moving through a mixer
- Roughly 600 flagged addresses are in circulation
The problem was not “Bitcoin got hacked.” It was messier and more ordinary: a firmware error in COLDCARD weakened the randomness used to generate seed phrases, as detailed in the Firmware Update Advisory for Coldcard Mk2, Mk3, Mk4, Mk5. That matters because a seed is the master backup for a wallet. If the seed is predictable enough, an attacker can reconstruct it offline, derive the same wallet addresses, and sweep funds without needing the device, the PIN, or any special access to the Bitcoin network.
That distinction matters. Bitcoin’s protocol still did what Bitcoin does. The failure happened in the wallet’s entropy, the randomness that is supposed to make a seed impossible to guess, something Coinkite later unpacked in its Technical Deep Dive into the Entropy Issue. Cold storage is only as cold as the math behind it. If the math is sloppy, the “hardware wallet” starts looking a lot less like a fortress and a lot more like expensive false confidence.
Galaxy Research has been tracking several attacker clusters tied to the flaw. Its latest on-chain monitoring shows the largest known cluster still holding 1, 159 BTC across seven addresses, with no sign that those coins have been sent to a mixer or to an identifiable cash-out service. A separate cluster, by contrast, has started routing smaller amounts through a mixer, apparently to break the transaction trail.
For readers newer to this corner of crypto, a mixer is a service or transaction pattern that combines funds and redistributes them in a way that makes tracing harder. It does not magically erase blockchain evidence. It just makes the job messier, noisier, and more dependent on pattern analysis. Think less “invisibility cloak” and more “throwing mud on a camera lens.”
The exact flow matters. In the mixer activity reported here, roughly 64 BTC was sent toward a mixer, about 10 BTC was initially mixed, around 54 BTC returned as change, and the remaining funds were split into outputs of roughly 7 BTC each for further mixing. That kind of repetitive structure can actually help investigators, because blockchain analysis often looks for odd transaction signatures, repeated output sizes, and shared spending patterns. Criminals like to think they’re clever. The chain has a long memory.
Galaxy says it has distributed roughly 600 flagged addresses to law enforcement, exchanges, and analytics firms. “Flagged” does not mean frozen. Bitcoin transactions cannot be stopped at the protocol level just because an address has been marked suspicious. What it does mean is that if those coins eventually hit a compliant exchange or another regulated cash-out point, monitoring systems may trigger checks that tie the flow to a real-world identity.
That chokepoint is often where blockchain tracing becomes most useful. On-chain investigators can follow the funds, cluster related addresses, and identify suspicious behavior. But if a thief never makes the mistake of using a regulated venue, the chances of recovery get a lot worse. Transparency helps. It does not guarantee justice.
Coinkite, the company behind COLDCARD, has released corrected firmware. It has also been clear about the uncomfortable part: updating firmware does not repair a seed that was already generated with the vulnerable version. If a seed was created under the flawed randomness conditions, the only safe move is to create an entirely new seed and move funds to addresses derived from it.
That is the part many users want to hear less than “everything is fine.” Unfortunately, crypto does not care about vibes. A seed phrase is only as safe as the randomness that created it. If the generation process was weak, an attacker may be able to narrow the possible outcomes enough to reconstruct the wallet offline. The device can still be sitting in a drawer while the underlying wallet is already compromised.
There is a nuance worth keeping in view, though. Coinkite says risk depends on the model, firmware version, whether enough fair and independent dice rolls were added during setup, and whether a strong unique BIP-39 passphrase was used. Dice rolls are exactly what they sound like, user-supplied randomness added during setup. A BIP-39 passphrase is an optional extra password layered on top of the seed phrase. Both can add protection, but they are not a substitute for fixing a vulnerable seed if one was created under unsafe conditions. That is the ugly part behind a lot of the chatter around the If Coldcard acknowledged the seed generation flaw debate. Users wanted transparency, and they were right to demand it.
The research figures around the broader theft have also evolved as more data has come in. Earlier reporting cited 1, 596 BTC stolen from approximately 7, 300 addresses across three attack waves, with a suspected fourth wave potentially lifting the total to around 2, 055 BTC if confirmed. Galaxy later identified additional suspected activity and also reported an observed estimate of 1, 367.05 BTC across 4, 585 addresses. Those numbers are not cleanly interchangeable. They reflect different snapshots and different levels of confirmation in a live investigation. Coverage from Two More Waves Raise Suspected Coldcard-Linked Losses to and Coldcard Hardware Wallet Hack: Over $100 Million in Bitcoin helped push the issue into wider view, while the Coldcard firmware seed-generation bug drained about 594 BTC from roughly 500 wallets framing underscored how quickly weak entropy can turn into a very expensive mess.
That is normal for on-chain forensics. Analysts are not reading a neat confession from the blockchain. They are piecing together patterns, matching transaction behavior, and separating confirmed victim reports from suspected weak-seed addresses. The chain is public, but public does not mean simple.
There is also a broader lesson here that crypto keeps relearning the hard way: “offline” is not a magic spell. Hardware wallets reduce attack surface, but they do not eliminate trust in the software that creates the seed in the first place. If the randomness is broken, the whole security model starts to wobble. That is not a failure of Bitcoin. It is a failure of implementation, and implementation is where most real-world security mistakes live. And yes, the faster this sort of issue gets addressed, the better. As the Coldcard Exploit Drives Bitcoin Onchain Activity to 2026 spike showed, fear alone can move markets and chain activity in ugly ways.
Coinkite’s response has been to patch the issue, release corrected firmware, and tell affected users to migrate to a new seed. Reports also indicate the company halted shipments and destroyed remaining inventory made with vulnerable firmware. That is the kind of hard stop you want when a wallet vendor discovers that its core security assumption was wrong. Anything less would be corporate nonsense dressed up as caution. For users trying to separate rumor from reality, the Coldcard Firmware Bug Drained Bitcoin After Weak Seed report makes the operational risk painfully clear, while the larger market shock was summed up by the Coldcard flaw tops $100M as David Schwartz warns self-custody has real risk angle.
Key questions and takeaways
-
Was Bitcoin itself broken?
No. The flaw was in COLDCARD’s seed-generation firmware, not in Bitcoin’s protocol. The network still worked as designed; the wallet’s randomness did not. -
Can a firmware update fix an old vulnerable seed?
No. Coinkite says updating firmware does not repair an existing seed. Anyone who created a seed under the vulnerable conditions needs to generate a new one and move funds. -
Why does the 1, 159 BTC cluster matter if it has not moved?
Because unmoved coins are still traceable and may be intercepted if they ever touch a compliant exchange or other regulated cash-out service. That gives investigators a window, even if it is not a guarantee. In this case, one Coldcard attacker holds 1, 159 BTC as mixing starts while the other side of the trail keeps getting fuzzier. -
Why do mixers raise concern?
They are often used to obscure transaction trails, which makes tracing harder for investigators. They do not erase evidence, but they can slow the work and muddy attribution. -
Are all COLDCARD users equally exposed?
No. Exposure depends on whether a seed was created on vulnerable firmware and under vulnerable conditions. Firmware version, added dice-roll randomness, and use of a strong unique BIP-39 passphrase all matter.
The upside is still real. Bitcoin’s public ledger makes stolen coins harder to vanish cleanly, and investigators can flag suspicious activity in ways the old banking system often cannot. The downside is equally real: if the attacker never slips up at a regulated chokepoint, those coins may just sit there, visible but unreachable.
Self-custody is powerful. It is also unforgiving. If the seed generation step goes wrong, there is no customer support desk in the sky. Verify the firmware, understand the entropy, and if a wallet was created under the vulnerable COLDCARD conditions, move it before someone else does.