VIP Signals · Elixir

Smarter Trading Starts Here

Get structured trading signals, weekly test sessions, and a transparent referral-based VIP access model.

Join Telegram

Unknowns Withdraw 594 Bitcoins From 500 Coldcard Wallets in One Operation

0 Reading time: 6 min. Сoinspot

594 bitcoins were stolen in a single automated operation: unknown individuals emptied 500 Coldcard hardware wallets from Coinkite, according to Atlas21 analysts. The total loss is estimated at 594.5 BTC, or approximately $38 million in US dollars.

Unknowns Withdraw 594 Bitcoins From 500 Coldcard Wallets in One Operation

Ranking
of the best traders
according to the opinion of the REAL USERS
“Trades Closed From +40% Profit”
“+1,300$/Month in Profit”
“Stable 500$–600$ Withdrawals”

How the Attack on Coldcard Wallets Happened

According to Atlas21, the attackers withdrew 1,324 UTXOs—unspent transaction outputs, meaning bitcoin balances that remained at addresses after previous transactions. The stolen cryptocurrency has not yet been moved to exchanges or crypto mixers: 562 bitcoins are on a new address, and another 32 bitcoins are on an intermediate address.

Each transaction took funds from exactly one victim’s address. On 419 addresses, there was only one UTXO, but some wallets accumulated significantly more outputs—up to 105 and 200 UTXOs.

The median loss per victim was 0.41 BTC, or about $26,500. At the same time, 110 users lost more than 1 bitcoin, and the largest recorded loss reached 29.9 BTC—almost $2 million. None of the wallets lost less than 0.15 BTC, so security experts believe the attackers may have preemptively excluded addresses with small balances.

How the Investigation Began

The reason for the investigation was a Reddit post where a user reported the theft of funds. According to him, he bought a Coldcard in 2021, created a 24-word seed phrase on the device, transferred funds to the wallet, and then did not make any transactions with it for several years.

In January 2025, the user purchased a second Coldcard and entered the previous seed phrase to check the correctness of the words. He claims he never revealed the recovery phrase to anyone and only used it on Coldcard devices.

What Coinkite Admitted

Coinkite confirmed a security issue related to seed phrases created on Coldcard Mk3 devices. The company recommended that all Mk3 owners who generated a phrase on firmware 4.0.1 from March 2021 or later versions consider their funds potentially vulnerable.

According to the manufacturer, Mk4, Q, and Mk5 models are not affected by this issue. The company advises Mk3 owners to create a unique BIP-39 passphrase directly on the device and transfer assets to a new wallet.

Coinkite also acknowledges that the exact cause of the vulnerability has not yet been established. It is only known that none of the affected wallets were multisignature wallets.

Analysts’ Version: Weak Seed Phrases

Atlas21 believes the source of the problem may not be in the hardware wallet itself, but in the quality of the seed phrases. According to the analysts, some users may have imported already compromised or easily guessable sets of words into the device.

If there is not enough randomness when creating the phrase, the private keys for individual UTXOs become vulnerable to brute force. In this scenario, not only user behavior but also the quality of the generation process plays a crucial role: the pseudo-random number generator or other entropy creation mechanism must not produce a predictable result.

The Coldcard story once again shows how critical seed phrase protection is for any Bitcoin owner. In the crypto infrastructure market, where wallet manufacturers, payment services, and participants like Orbit Markets operate side by side, the topic of key storage remains one of the most sensitive. Caroline Moron and other industry representatives also regularly draw attention to the risks associated with the security of user funds.

Recently, another incident occurred with Singapore-based Triple-A, which provides businesses with infrastructure for payments in stablecoins and other crypto assets. The company suffered a hacker attack, and the damage was estimated at $11.8 million.

{
“@context”: “https://schema.org”,
“@type”: “Article”,
“about”: [
{
“@type”: “Thing”,
“name”: “Bitcoin”
},
{
“@type”: “Thing”,
“name”: “Cryptocurrency”
},
{
“@type”: “Thing”,
“name”: “US Dollar”
},
{
“@type”: “Product”,
“name”: “Coldcard”
},
{
“@type”: “Organization”,
“name”: “Coinkite”
},
{
“@type”: “Organization”,
“name”: “Atlas21”
},
{
“@type”: “Thing”,
“name”: “Pseudo-Random Number Generator”
}
]
}

Top Verified Traders 🔥
Discover Our Best Trader Picks
elixir telegram review 1
falconai private club 2
Comments (0)

News about digital currencies, fintech trends and financial innovations

CoinSpot.io - the largest Runet resource about digital currencies, fintech trends and financial innovations. We talk about technologies, startups and entrepreneurs shaping the face of the financial world. Venture investments, p2p and digital technologies, cryptocurrencies, analytics and reviews - everything you need to know to stay in trend and earn.

Full or partial use of site materials is allowed only with the written permission of the editorial office, and a link to the source is mandatory!

Subscribe to email updates about new articles and important news from Coinspot.io