
A five-year-old software vulnerability in Coldcard, a popular Bitcoin hardware wallet, may have enabled attackers to reconstruct private keys and drain funds from users, with more than 1,100 BTC potentially swept across a coordinated series of transactions. The incident surfaced after roughly 594 BTC—valued at about $38 million at the time—was moved in a rapid sequence of withdrawals. The wallet’s maker suggested the flaw’s discovery may have been aided by advances in artificial intelligence tools.
Coordinated Sweep Empties Hundreds of Wallets
On-chain activity indicating a synchronized “sweep” drew attention after approximately 594 BTC left impacted wallets in quick succession. Early assessments indicate the total losses could exceed 1,100 BTC across numerous addresses. While the precise method used by the attacker has not been fully detailed, investigators and community analysts are attributing the theft to an underlying software issue that exposed private key material.
Five-Year-Old Vulnerability Implicated
The flaw, described as dating back about five years, may have allowed an attacker to reconstruct private keys under certain conditions. Coldcard, produced by Coinkite, is a Bitcoin-only hardware wallet designed to keep private keys offline. The company acknowledged the issue and indicated that modern AI tooling may have helped the attacker identify the weakness, though a full technical breakdown had not been published at the time of writing.
User Impact and Immediate Guidance
Users who generated seeds or interacted with affected software during the relevant period could be at risk. Until a definitive advisory and remediation details are available, security practitioners recommend taking precautionary steps:
- Move funds to a freshly created wallet using a newly generated seed phrase.
- Obtain the latest official firmware and wallet software directly from the vendor and verify authenticity before use.
- Use strong passphrases and consider multisignature setups to reduce single-device compromise risk.
- Monitor addresses and transaction history for unauthorized activity.
- Beware of phishing attempts and rely only on official communication channels for updates.
Why It Matters
Hardware wallets are a cornerstone of self-custody in Bitcoin, and any vulnerability affecting key generation or storage can have far-reaching consequences. The developing situation underscores the importance of rigorous code review, reproducible builds, and timely security disclosures, as well as defense-in-depth practices such as multisig and passphrase protection.