The theft moved 1,324 chunks of bitcoin across 500 transactions inside a three-block window, with 562 BTC then consolidated into a single address that has not moved.
Every drained wallet was single-signature and each held more than 0.15 BTC. Many had been dormant for years and the coins spanned 2021 to 2026, matching the flaw's age almost exactly.
Coldcard is a hardware wallet built by Canadian firm Coinkite, a small standalone device that stores bitcoin keys offline, away from internet-connected computers. Mk2, Mk3, Mk4, Q and Mk5 are successive generations of that product, released over several years the way a phone maker ships numbered models.
Exposure depends on the firmware the device was running at the moment the wallet was first created, not on when the hardware was bought.
A wallet's seed, the secret phrase controlling the funds, is meant to be drawn at random from a pool so vast that guessing is hopeless.
Coldcard's firmware was not doing that. According to a report published by Block's Bitcoin engineering and security teams, a build setting told the device to skip its own hardware randomness generator, and a check in a supporting library tested only whether that setting existed rather than whether it was switched on.
Key generation quietly fell through to a basic software substitute seeded from the chip's serial number and clock registers.
None of those are secrets. The serial number is fixed factory metadata, and the clock values are timing state an attacker can narrow down or measure on a device of their own. Block traced the change to a commit dated March 1, 2021, shipped in firmware 4.0.0 that month.
As such, Coinkite warned users who generated a seed on an Mk3 running version 4.0.1 or later, and said "Mk4, Q and Mk5 are not affected based on our early analysis."
Block said it disclosed its findings to Coinkite, whose team acknowledged them. Both companies describe their analyses as preliminary, and Block said it published without full testing to confirm exploitability because exploitation was already under way.
The exposure runs past wallet seeds. The same generator produced Coldcard's paper wallet private keys, where the output becomes the key directly with no further derivation, along with seed-splitting masks, device cloning keys and Key Teleport transfers.
Bitcon traded above $64,000 in early Asian hours, with widespread drain appearing to have little impact on the market.
1 Bitcoin holds monthly gain, faces 'choppy' August as 'forced-selling' exhausted, analysts say 49 minutes ago 2 Tether posts $1.5 billion operating profit in Q2 as reserve buffer falls by half 3 hours ago 3 The good and the bad of perps, according to crypto traders 3 hours ago 4 Coldcard's $38 million (so far) exploit shakes faith in self-custody, may push investors to ETFs 4 hours ago 5 Quantum computing nears commercial breakthrough, IBM CEO says 6 hours ago 6 Crypto faces 3 barriers to next bull run, STS Digital CEO says 6 hours ago 7 Circle secures New York trust charter as crypto regulatory push accelerates 8 hours ago 8 Coinbase's weak quarter leaves Wall Street split on timing of a recovery 8 hours ago 9 RWA perps will outpace tokenization 8 hours ago 10 Dubai-based crypto exchange tied to $4 billion Iran sanctioned-evasion network 9 hours ago Latest Research The Evolution of the Crypto CEX Landscape: A Case Study on Binance The Evolution of the Crypto CEX Landscape: A Case Study on Binance Binance remains crypto’s leading exchange, expanding from spot and derivatives into RWAs, payments, savings, yield, and broader financial services.
Binance remains crypto’s leading exchange, expanding from spot and derivatives into RWAs, payments, savings, yield, and broader financial services.