A firmware flaw that shipped in March 2021 made Coldcard hardware wallet seeds guessable offline, and attackers have swept roughly 1,816 BTC across four waves since Thursday, totaling approximately $114 million. The latest wave on Monday moved 448.7 BTC from 709 addresses at 13.8 sweeps per block — 45 times the pre-incident rate — according to Galaxy's Alex Thorn. The bug routed seed generation through a predictable software randomizer instead of the device's hardware RNG, allowing anyone who can constrain the device serial number and boot timing to reproduce the private key. Coinkite released emergency firmware within hours of the first wave Thursday and has told users to generate fresh seeds and migrate funds immediately.
This breaks the foundational trust model of hardware wallets — that keys generated on-device cannot be guessed — and creates two immediate market effects. First, it removes roughly $114 million in forced-hold supply from addresses that believed their bitcoin was in cold storage, turning what holders thought was secure into liquid coins for attackers to sell or consolidate. Second, it injects execution risk into the remaining vulnerable UTXO set: Thorn estimates more than 5,200 addresses hit so far, and any address created on affected firmware between March 2021 and this week remains at risk until the holder migrates to a new seed. The Monday wave opted into replace-by-fee, giving victims a narrow window to outbid the attacker in the mempool before confirmation, but that window closes once the sweep confirms. The attacker also shifted to sending each victim's funds to a fresh unused address instead of converging on shared collection wallets, making flow-tracing harder.
The snapshot shows funding at +0.7 basis points per eight hours, modestly above the 30-day average of +0.5, and Fear & Greed at 34 — above the 30-day baseline of 28 but still in fear territory. The elevated fear reading likely reflects the breach itself rather than any cascade effect, and funding has not collapsed despite $114 million in potential sell pressure. That suggests the market is pricing this as reputational damage to one device maker rather than a sector-wide hardware wallet failure. Coldcard holds a niche position among users who prioritize open-source verification and air-gapped signing, so the breach damages that specific trust vertical without necessarily spilling into other hardware wallet holdings. Still, the breach lands at a time when hardware wallet security directly affects self-custody confidence, and any headline pairing "hardware wallet" with "$114 million theft" reinforces the custody-outsourcing trade.
Watch two things: whether the rate of sweeps accelerates as attackers race to drain the remaining vulnerable set before victims update firmware and migrate, and whether any large address — over 100 BTC — appears in the mempool with a replace-by-fee flag, signaling a victim attempting an outbid rescue. If sweep velocity climbs above 15 per block or a major holder loses a public mempool race, expect another leg down in sentiment toward self-custody.
Source: The Defiant
