Skip to content Skip to sidebar Skip to footer

A Hidden Flaw? Investigators Search for the Cause Behind a $38M Bitcoin Theft

A potential security flaw affecting older Bitcoin hardware wallets has prompted renewed scrutiny from cybersecurity researchers after nearly $38 million worth of Bitcoin was drained from hundreds of wallets in a coordinated operation.

The incident involved the movement of 594.48 BTC from single-signature wallets, raising concerns that a weakness in wallet seed generation may have been exploited. While investigators have not confirmed the source of the vulnerability, several experts believe the affected wallets may share a common issue related to insufficient randomness during seed creation.

The investigation gained momentum after a Bitcoin holder reported on Reddit that funds had been stolen from a wallet originally created on a Coldcard Mk3 device purchased in 2021. The user later restored the same recovery seed onto a newer Coldcard Mk4 in early 2026. Although the claim remains unverified, it has drawn attention because it coincides with the larger pattern of coordinated theft.

Blockchain analysis by AnchorWatch CEO Rob Hamilton found that 1,324 unspent transaction outputs (UTXOs) were consolidated through roughly 500 transactions within the span of just three Bitcoin blocks. The stolen funds, valued at approximately $38.3 million at the time of analysis, were later merged into a single destination wallet, suggesting a highly organized operation.

Hamilton noted that every compromised wallet used a single-signature setup, adding that the transaction pattern appeared consistent with wallets generated from weak cryptographic entropy. Rather than random chance, the attack may have targeted wallets whose recovery seeds were created using predictable random-number generation.

Kevin Loaec, CEO of Wizardsardine, proposed that the underlying weakness could originate from a low-entropy random-number generator embedded in a software library, secure element, manufacturing batch, or a specific firmware release. If so, an attacker with knowledge of the flaw could systematically reconstruct vulnerable wallet seeds instead of attacking wallets through conventional brute-force methods.

According to Loaec, the attacker may have automated the search process with AI-assisted tooling while limiting scans to a narrow range of BIP-84 derivation paths. This could explain why the theft primarily affected native SegWit wallets and why some wallets lost only part of their holdings. However, he emphasized that the theory has not yet been verified.

Meanwhile, Canadian hardware wallet manufacturer Coinkite has advised owners of Coldcard Mk3 devices running firmware versions between 4.0.1 and 5.0.3 to migrate their funds as a precaution. The company said newer devices—including the Mk4, Mk5, and Coldcard Q—are not impacted based on its current findings.

As a safety measure, Coinkite recommends generating a new recovery seed on an unaffected device, verifying the backup and receiving address, performing a small test transfer, and only then moving the remaining Bitcoin. The company also noted that wallets protected with a BIP-39 passphrase appear to face significantly lower risk, while stressing that its technical investigation is still ongoing.

Although no direct evidence currently links the Coldcard Mk3 firmware issue to the coordinated theft, security researchers continue to examine whether both events stem from the same underlying weakness in wallet seed generation.

Leave a comment

Email

Email