594 BTC Stolen From 500 Wallets as Coldcard Seed Flaw Investigated

594 BTC Stolen From 500 Wallets as Coldcard Seed Flaw Investigated

Last Updated:
594 BTC Stolen From 500 Wallets as Coldcard Seed Flaw Investigated
Google News

Get our latest news first. Add us as your Preferred Source on Google and tap "Star" to prioritize our updates.

  • Coinkite warns Coldcard seed flaw may be linked to theft of 594 BTC from about 500 wallets.
  • Researchers say affected wallet seeds may date back to 2021 as investigation continues.
  • Additional transactions could raise the total stolen to about 1,082 BTC if confirmed.

A security warning from hardware wallet maker Coinkite coincided with the discovery of a large-scale Bitcoin theft that emptied hundreds of wallets within minutes, prompting renewed scrutiny of wallet seed generation.

Approximately 594 BTC, valued at about $38 million, was drained from around 500 single-signature wallets during a set of transactions. While blockchain researchers have linked the incident to a flaw affecting certain Coldcard wallet seeds, Coinkite has not confirmed that the vulnerability caused the theft.

The stolen funds moved through 1,324 transaction outputs spread across 500 transactions within a three-block window. Later, 562 BTC was consolidated into a single address that has not moved. The affected wallets each held more than 0.15 BTC, and many had remained inactive for years, with coins dating from 2021 through 2026.

According to report from Atlas 21, the issue is tied to firmware rather than the physical hardware itself. The company said any Bitcoin seed generated on a Coldcard Mk3 device since March 2021 could be vulnerable because of reduced randomness during seed creation.

Coinkite Researchers Examine Scope of the Incident

Although Coinkite initially stated that only the Coldcard Mk3 was affected, its later advisory noted that newer models, including the Mk4, Q, and Mk5, also generate seeds with 72 bits of entropy instead of the intended 128 bits because of a different implementation. The company said its early analysis did not identify those models as affected in the same way.

Bitcoin developer James O’Beirne urged users whose funds were protected by a single key generated on a Coldcard Mk3 between 2021 and 2023, without additional protections such as dice-generated entropy, a passphrase, or multi-signature security, to move their funds promptly. He also said the Mk2 and Mk4 may require further review despite Coinkite’s preliminary assessment.

Meanwhile, Block engineer Clay Garrett identified another 695 transactions sharing the same characteristics as the confirmed thefts. Those transactions transferred an additional 488.1 BTC, raising the possibility that the total amount could reach about 1,082 BTC if all transactions are ultimately linked. 

Related: Frozen Bitcoin Wallet Exposes $1M Crypto Scam Network

Disclaimer: The information presented in this article is for informational and educational purposes only. The article does not constitute financial advice or advice of any kind. Coin Edition is not responsible for any losses incurred as a result of the utilization of content, products, or services mentioned. Readers are advised to exercise caution before taking any action related to the company.