A reported Coldcard Bitcoin hack could approach $114 million in potential losses as a possible fourth sweep of affected wallets emerges, raising fresh concern over the hardware wallet’s seed generation on older devices.
What Is Known About the Coldcard Bitcoin Hack So Far
The incident centers on Coldcard, the Bitcoin hardware wallet made by Coinkite, and stems from a flaw in how seed phrases were generated on certain older devices. Coinkite has published a seed generation warning for Coldcard Mk3 users describing the risk. For related coverage, see Coldcard Exploit Highlighted in August 2 Hodler's Digest.
The underlying technical issue has been documented as a predictable random number generator fallback combined with a 32-bit reseed in Coldcard firmware, according to a Block engineering analysis. A weakened source of entropy can make a wallet’s private keys guessable by an attacker.
The situation remains active rather than closed. As we reported when the Coldcard exploit entered its fifth day, funds have continued to move from affected wallets while the investigation is ongoing. Attribution and a final total have not been confirmed.
How the Potential Losses Could Near $114 Million
The headline figure is framed as potential rather than confirmed. Reporting indicates that Coldcard wallet losses may near the $114 million mark as a possible fourth sweep of vulnerable wallets emerges, according to CoinDesk.
The estimate reflects exposure tied to wallets generated with weak entropy, not a single verified tally of stolen funds. Because sweeps have occurred in waves, the running figure can shift as additional affected addresses are drained or identified, which is why the total is described as an estimate.
Our earlier coverage tracked the same trajectory, noting that Coldcard wallet losses were nearing the same level as a possible fourth sweep emerged. Any recoveries, freezes, or misattributed movements could change the final number in either direction.
What the Incident Means for Coldcard Users and Bitcoin Self-Custody
For users, the immediate concern is whether their device generated its seed on affected firmware. Coinkite’s warning to Coldcard Mk3 users following the reported 594 BTC theft points holders toward checking their device generation and moving funds to a newly and securely generated seed if at risk.
The episode is a direct hit to Coldcard’s reputation, given that hardware wallets are marketed on the strength of their key generation and cold storage security. A flaw at the entropy layer strikes at the core promise of the product.
One account documenting the sweeps has drawn attention within the community. The following post from @intangiblecoins is cited among the discussion of the ongoing wallet drains.
Source: @intangiblecoins on X
The broader lesson lands on the self-custody narrative: holding your own keys removes counterparty risk but shifts full reliance onto the correctness of the device and its firmware. This incident stands alongside other custody failures, such as the recent case where ZeroStack warned of survival risk after an $82.5 million loss, as a reminder that implementation details carry real financial weight.
Disclaimer: This article is for informational purposes only and does not constitute financial or investment advice. Cryptocurrency and digital asset markets carry significant risk. Always do your own research before making decisions.
