A firmware bug hiding in Coldcard hardware wallets since March 2021 finally bit. Starting July 30, attackers exploited a randomness flaw in the popular cold storage device to drain approximately 2,100 BTC, worth between $116M and $130M, from over 5,200 addresses.

What happened next, according to Casa CEO Nick Neuman, matters far more than the theft itself. Roughly 233,000 BTC moved from long-term holder wallets in the days that followed, as users scrambled to rotate funds into safer setups. For every Bitcoin stolen, more than 100 were proactively secured.

The exploit and the exodus

The vulnerability traced back to a flaw in how Coldcard’s firmware generated randomness for private keys. Devices running affected firmware versions produced keys with insufficient entropy, making them guessable given enough computing power and time. The bug had been sitting in production code since March 2021, meaning wallets generated over a five-year window were potentially at risk.

Coinkite, the company behind Coldcard, issued an emergency firmware patch on July 31, one day after the exploit began. The company advised users to immediately update and migrate their funds using freshly generated keys.