The security crisis surrounding Coldcard hardware wallets has taken a dramatic turn, with blockchain researchers estimating that approximately 1,367 Bitcoin, worth around $88.6 million, may have been stolen from 4,585 Bitcoin addresses.
The latest estimate, attributed to analysis by Galaxy Research, is significantly higher than the initial reports of roughly $38 million in losses. Investigators say the suspected thefts appear to be connected to a vulnerability affecting the way certain Coldcard devices generated wallet seeds.
What Happened?
The issue involves the generation of cryptographic seeds, which are the foundation of a Bitcoin wallet’s private keys. Under normal circumstances, hardware wallets use highly unpredictable randomness to generate these seeds.
According to security researchers, certain Coldcard firmware versions could use a deterministic software-based random number generator under specific circumstances. This potentially reduced the randomness available during seed generation and may have made some wallet seeds vulnerable to reconstruction.
The vulnerability is particularly serious because a compromised seed remains vulnerable even if the hardware wallet is later updated.
Losses Reportedly Occurred in Multiple Waves
Blockchain analysis identified several waves of suspicious transactions.
The largest reported wave involved more than 1,080 BTC being drained from approximately 1,200 addresses. Additional transactions later targeted thousands of other addresses.
Combining the suspected transactions, Galaxy Research estimated that around 1,367 BTC across 4,585 addresses may have been affected, putting the potential value of the losses at approximately $88.6 million.
However, the figure remains an estimate. On-chain analysis can identify suspicious patterns, but researchers cannot yet confirm that every address included in the calculation was compromised specifically because of the Coldcard vulnerability.
Updating the Device May Not Be Enough
One of the most important warnings for Coldcard users is that simply installing updated firmware does not necessarily protect an existing wallet.
If a seed was generated while the vulnerable software was being used, the seed itself may already be compromised. In that situation, upgrading the device does not make the original seed unpredictable again.
Affected users are therefore advised to generate a new wallet seed using secure, updated firmware and transfer their Bitcoin to the new wallet.
Users who generated their seeds using sufficient independent dice-generated entropy may have additional protection against this particular vulnerability, although anyone uncertain about how their seed was created should carefully review Coldcard’s security guidance.
A Major Warning for Bitcoin Self-Custody
The incident has broader implications for the cryptocurrency industry. Hardware wallets are widely considered one of the safest ways to store Bitcoin, but the Coldcard case demonstrates that even offline self-custody can be affected by flaws in key generation.
The suspected theft also highlights an important principle of Bitcoin security: protecting the physical device is only part of the equation. The randomness used to create the wallet’s original private keys is equally critical.
With potential losses now approaching $90 million, the Coldcard incident is becoming one of the most significant hardware-wallet security events in recent years.
The investigation remains ongoing, and the final amount stolen could change as researchers identify additional affected addresses or rule out transactions that were initially considered suspicious. For Coldcard users who may have generated wallets with vulnerable firmware, however, the message is clear: do not assume an old wallet is safe simply because it has never been compromised before.



