Coldcard attack: 25 minutes, 500 wallets, $38M in BTC gone

Someone likely used AI to drain almost 600 BTC, worth $38 million, from roughly 500 dormant wallets yesterday as part of a seed phrase exploit targeting Coldcard hardware wallets.
The attack took just 25 minutes to move the BTC from 500 single-signature addresses into a single address, and reports suggest the exploit will likely continue.
Coindesk reports that the affected BTC was dated between 2021 and 2026, and much had remained dormant for years. Of the 594 coins stolen, 562 remain in the same address at the time of writing.
Coldcard maker, Coinkite, confirmed hours after the exploit that seed generation within its Mk3 wallet, and its subsequently updated versions beyond March 2021 (version 4.0.1), may not have been random at all.
Coldcard initially claimed that its Mk3 devices were at risk, and that the Mk4, Q, and Mk5 are “not affected based on our early analysis.”


