A major Bitcoin theft has sparked fresh concerns about hardware wallet security after approximately 594 BTC, valued at around $38 million, was drained from hundreds of wallets during a coordinated attack.
The incident unfolded within roughly 25 minutes, with blockchain analysts reporting that funds from nearly 500 single-signature Bitcoin wallets were consolidated into a single address after being swept across multiple transactions.
Security researchers are investigating whether the theft may be linked to an alleged vulnerability affecting certain Coldcard Mk3 hardware wallets.
Hundreds of Wallets Drained
According to early blockchain analysis, the attacker rapidly transferred more than 1,300 UTXOs across several Bitcoin blocks before consolidating the stolen funds.
Many of the affected wallets had remained inactive for years, with some coins dating back to 2021.
Researchers noted that the wallets were predominantly:
- Single-signature wallets
- Legacy or SegWit addresses
- Long-term storage wallets
- Not protected by multisignature configurations
The speed and coordination of the attack have led investigators to believe the wallets may have shared a common weakness.
Researchers Examine Possible Firmware Flaw
Preliminary reports suggest investigators are examining whether a historical randomness (entropy) issue in certain Coldcard Mk3 firmware versions may have contributed to the compromise.
According to researchers, the alleged flaw could have reduced the randomness used during seed generation under specific circumstances, potentially making some private keys more predictable than intended.
The findings remain under investigation, and the full scope of any vulnerability has not yet been officially confirmed.
Manufacturer Issues Guidance
Following reports of the incident, Coinkite, the manufacturer of Coldcard hardware wallets, advised users who generated recovery seeds on potentially affected firmware versions to review their wallet security.
The company recommended that users who believe they may be impacted:
- Generate a new recovery seed using updated hardware or firmware
- Move funds to newly created wallets
- Verify backups before transferring assets
- Ignore unsolicited recovery offers or support messages
Coinkite also indicated that newer Coldcard models are not believed to be affected based on its preliminary assessment.
Self-Custody Still Requires Vigilance
The incident highlights one of the ongoing challenges of cryptocurrency self-custody.
Hardware wallets are widely regarded as one of the safest ways to store digital assets offline. However, security researchers note that vulnerabilities affecting firmware or key generation can remain unnoticed for years before being discovered or exploited.
For long-term holders who rarely interact with their wallets, historical software issues may pose risks that only become apparent much later.
Market Impact
Despite the scale of the theft, Bitcoin’s price showed little immediate reaction, with the broader cryptocurrency market remaining relatively stable.
Investigators continue tracking the stolen funds while security researchers work to determine whether the affected wallets were compromised through a shared vulnerability or another attack vector.
What Comes Next?
The investigation remains ongoing, with blockchain analysts, security researchers, and hardware wallet developers continuing to examine the incident.
Users who generated Bitcoin wallets several years ago are encouraged to review manufacturer security advisories, ensure their firmware is up to date, and consider migrating funds if recommended by official guidance.
The event serves as another reminder that while self-custody offers greater control over digital assets, maintaining long-term security requires ongoing attention to both hardware and software updates.









