Coldcard losses pass $100 million, and it is operational risk, not cryptographic risk
Seeds users believed were generated securely on air-gapped devices were guessable. That is a firmware failure, and it says nothing about the protocol.
Confirmed losses linked to the Coldcard hardware-wallet vulnerability have surpassed $100 million. Galaxy Research now estimates 1,596 BTC stolen from approximately 7,300 addresses across three confirmed attack waves plus 14 smaller incidents. A suspected fourth wave, if verified, would raise the total toward 2,055 BTC.
The important framing, and the one most coverage gets wrong, is that this is operational risk. It is not a cryptographic failure.
What actually broke
The root cause is a firmware-level seed-generation flaw. Affected Coldcard models, including certain Mk3, Mk4, Mk5 and Q versions, failed to use a proper hardware random number generator and fell back to a predictable software process. Seeds that users believed were securely generated on air-gapped devices were in fact guessable, and attackers exploited that to drain funds in coordinated waves.
Coinkite has released emergency firmware updates and stated that remaining vulnerable inventory has been destroyed. Most of the stolen coins have not yet been moved from the initial consolidation addresses.
Why the distinction is not pedantry
Bitcoin's elliptic-curve security is intact. Nothing about this event says anything about the protocol. The failure sat at the device and firmware layer, which is precisely the layer self-custody assumes the user has already handled.
That is uncomfortable, because it is the part of the stack that receives the least scrutiny. A great deal of attention goes to speculative future threats to the cryptography itself. Almost none goes to whether the random number generator in a specific firmware build did what its documentation claimed. This episode is a direct demonstration of which of those two risks has actually taken coins.
The hierarchy this establishes
Markets have continued to price Bitcoin primarily on macro and flow factors rather than treating the expanding loss total as a systemic event, which is the correct reading: the losses are large in absolute terms and contained in structural terms.
For the large majority of holders, the near-term threat ranking is firmware integrity, then seed-generation quality, then operational hygiene. Theoretical cryptographic risk sits below all three. An honest security posture spends its attention in that order rather than in the order the headlines suggest.