Key Points
- Coldcard firmware flaw exposed 2,055 Bitcoin (BTC) across 7,700 addresses.
- Attackers exploited weak seed entropy and executed multiple on-chain sweep waves.
Analytical estimates from Galaxy Research indicate that losses tied to the Coldcard vulnerability total about 2,055 Bitcoin (BTC), valued near $130 million, affecting more than 7,700 addresses.
The assessment follows reports of several suspected on-chain sweep waves linked to a seed-generation issue in devices produced by Coinkite.
The vulnerability involved how wallet seeds were generated on certain firmware versions, potentially enabling attackers to derive and test keys offline under specific conditions.
Coldcard Firmware Flaw and Entropy Concerns
A March 2021 firmware integration error redirected seed generation to a deterministic pseudorandom number generator instead of the STM32 hardware random number generator.
In the production setup, a configuration macro disabled the hardware generator, while the supporting library checked only for the macro’s presence rather than whether it was active.
As a result, the system relied on MicroPython’s Yasmarang fallback, which was initialized using chip identifiers and timer data without gathering additional entropy afterward.
Security analysis indicated that if an attacker could sufficiently determine device identifiers, timer states, and prior random-number calls, they could reconstruct possible output streams offline and compare derived addresses against public blockchain records.
Coinkite estimated effective entropy of approximately 40 bits for Mk3 hardware and around 72 bits for Mk4, Mk5, and Q models, compared with the 128-bit entropy expected from a standard 12-word BIP-39 seed.
The company released emergency firmware updates on July 31, but installing new firmware does not retroactively secure seeds already generated under vulnerable conditions.
Users with potentially exposed seeds were advised to generate new seeds on updated firmware and transfer their funds, as restoring an original weak seed would preserve the vulnerability.
On-Chain Activity and Sweep Patterns
On-chain analysis identified an initial sweep on July 30 that moved 1,082.65 BTC from 1,196 addresses within approximately 41 minutes.
This first wave averaged close to one BTC per affected address.
Further reporting by CoinDesk described a third suspected sweep that transferred about 208 BTC from 1,912 addresses.
In that later activity, transactions bundled roughly six victims per sweep, routed funds to separate destinations, and used pay-to-witness-script-hash outputs instead of single-key outputs seen previously.
Galaxy Research stated that each wave appeared internally consistent with a single operator, though on-chain evidence could not confirm whether the same entity conducted all three waves.
The firm also noted it had not computationally verified that every flagged address originated from weak Coldcard entropy but reported around 600 suspected attacker-controlled addresses to relevant investigative and compliance authorities.



