Roughly 594 bitcoin, worth about $38 million, was swept out of around 500 separate wallets between 01:31 and 01:56 UTC on Friday in an attack traced to a flaw in how Coldcard hardware wallets generated their keys.
The theft moved 1,324 chunks of bitcoin across 500 transactions inside a three-block window, with 562 BTC then consolidated into a single address that has not moved.
Every drained wallet was single-signature and each held more than 0.15 BTC. Many had been dormant for years and the coins spanned 2021 to 2026, matching the flaw’s age almost exactly.
Coldcard is a hardware wallet built by Canadian firm Coinkite, a small standalone device that stores bitcoin keys offline, away from internet-connected computers. Mk2, Mk3, Mk4, Q and Mk5 are successive generations of that product, released over several years the way a phone maker ships numbered models.
Exposure depends on the firmware the device was running at the moment the wallet was first created, not on when the hardware was bought.
A wallet’s seed, the secret phrase controlling the funds, is meant to be drawn at random from a pool so vast that guessing is hopeless.
