Firmware Flaw Let Attackers Pre-Profile Victims Before $38M Coldcard Heist
Chainalysis reveals attackers ranked Coldcard wallet victims by balance before striking, draining 500 wallets in 25 minutes via a firmware entropy flaw.
Chainalysis has confirmed that attackers behind the Coldcard hardware wallet exploit stole approximately $30 million in the first 10 minutes of their operation, deliberately prioritizing the highest-value addresses in a sweep that ultimately drained around 500 wallets within 25 minutes and exceeded $38 million in total losses.
Victims Were Profiled Before the First Transfer
The sequencing of the attack is what makes the Chainalysis findings particularly significant. According to the firm’s analysis, the attackers targeted high-value wallets first – including one address holding $1.8 million – indicating that victims had been profiled and ranked before any funds were moved. This was not opportunistic; it was a structured extraction designed to maximize yield before security teams could react.
The broader technical context, drawn from research by Galaxy Research and security analysts, points to a firmware flaw in Coinkite‘s Coldcard devices as the underlying enabler. A mis-written compile-time check in firmware version 4.0.1 and later – released after March 2021 – caused affected Mk3 and subsequent models to fall back to software-based randomness during seed generation rather than using the intended hardware RNG. Wallets generated on those devices carry predictably weak seeds, and an attacker who identified that flaw could systematically derive private keys across a class of addresses without ever touching the physical device.
Galaxy Research’s on-chain tracing connected approximately 1,196 addresses to the same seed-generation vulnerability. Of those, around 594 BTC had been stolen at the time of initial reporting, with roughly 562 BTC still consolidating in a single address – a holding pattern consistent with an attacker staging funds ahead of laundering.
A Paid Blockchain API Account Helped Map the Targets
Clay Garrett of Block confirmed a detail that extends the attack’s sophistication well beyond on-chain analysis: investigators determined that the attacker used a paid account from a well-known blockchain service provider to query victim addresses during the operation. The provider’s internal logs matched the timing and sequence of those requests precisely. Block stated it found no evidence the company knowingly assisted in the theft, and the information has been shared with authorities.
What this establishes is a pre-attack intelligence phase. Before the first satoshi moved, the attacker was running structured API queries – likely correlating on-chain balance data with the universe of addresses vulnerable to the weak-seed flaw – to build a ranked target list. The $1.8 million wallet being hit first is consistent with that methodology. This is closer to institutional-grade due diligence than a speculative sweep.
Investigators and security researchers have noted that the attacker likely used AI-assisted code analysis to identify the subtle entropy flaw in Coldcard’s open-source firmware, then precomputed or rapidly derived the exploitable seed space to identify drainable addresses at scale. The pattern – dormant single-signature wallets funded between 2021 and 2026, left untouched for years – suggests the target set was skewed toward long-term holders who had parked savings and walked away, not active traders monitoring balances daily.
What Coldcard Users Must Do Now
Coinkite has pushed emergency firmware updates, but technical analysis makes clear that a patch alone is not sufficient for seeds that were already generated on affected firmware. Wallets whose seeds were created on a Coldcard running firmware 4.0.1 or later, on Mk3 or subsequent hardware, are considered at risk according to security researchers. Users are urged to generate a new seed on fixed firmware and migrate all funds to fresh addresses.

This incident sits in a broader pattern of targeted, data-driven thefts against hardware wallet holders – a cohort that historically skews toward larger balances and longer holding periods, making them structurally attractive targets. A separate analysis of custody risks facing large Bitcoin holders notes that single-signature cold storage, once considered the security ceiling for retail investors, carries concentration risk that multi-sig setups are specifically designed to distribute.
The Coldcard attack is not the only recent example of sophisticated exploitation hitting crypto holders at the infrastructure level. A malware campaign targeting seed phrases through compromised gaming platform delivery demonstrated that attackers are willing to invest significant operational effort to reach hardware-wallet-level security assumptions. The common thread is that the attack surface has shifted from exchanges to the devices and software users trust most.
Recovery Prospects and What Investigators Are Tracking
Chainalysis and Galaxy Research are continuing to trace the stolen BTC, monitoring mixer activity and cross-chain bridge flows for laundering patterns that could support future sanctions designations or exchange-level freezes. The attackers moved swiftly to launder stolen funds through mixing services and cross-chain transactions, complicating recovery efforts – a pattern that has been documented in multiple major crypto theft cases.

The approximately 562 BTC still sitting in a consolidating address remains a focus for investigators. If that position moves toward a known mixer or a centralized exchange with KYC requirements, there is a narrow window for coordinated intervention. Whether law enforcement can close that window fast enough is the operative question the market will be forced to price into its assessment of hardware wallet security going forward.
Regulatory and standards bodies are expected to scrutinize hardware wallet RNG practices more closely following this incident. Coinkite has signaled further technical disclosures and post-mortem reporting once internal audits are complete, but the structural lesson is already clear: open-source firmware is not a security guarantee without continuous, external entropy audits – and for large holders, single-signature cold storage is a single point of failure, not a ceiling.
Follow CoinNews on X and Telegram for ongoing coverage of crypto security incidents and market-moving developments.