A newly surfaced firmware flaw at Coinkite’s Coldcard wallet is being linked to theft from more than 5,200 Bitcoin addresses, totaling about 1,816 Bitcoin, or roughly $116 million. The issue did not stem from breaking into hardware, but from a subtle weakness introduced in a March 2021 software update. That change allegedly reduced entropy, the randomness used to create a wallet’s recovery seed. Instead of always relying on a hardware random-number generator, affected firmware could fall back to a more predictable software process. If that randomness is weak enough, attackers can generate likely seeds on their own systems, derive the wallet addresses those seeds would produce, and match them against funded addresses on the blockchain.
The crucial point is that a flawed seed from years back can remain a ticking time bomb, compromising funds long after generation. That is what separates this incident from physical wallet hacks: the risk sits in seed creation, not a device being physically breached or lost. Updating firmware now would not protect Bitcoin already secured with weak seeds. In those cases, the funds would need to be moved to a wallet created from a new seed. The broader lesson is that offline storage alone does not remove risk if seed generation can be modeled by an attacker.