A hardware wallet security crisis is deepening at a pace that should alarm anyone holding Bitcoin in cold storage. A suspected fourth wave of coordinated attacks on Coldcard hardware wallet users is now underway, with 462 new suspected victims identified — piling onto an already staggering toll of 1,367.05 Bitcoin (BTC) drained from 4,585 addresses across three previously confirmed waves. The exploit at the center of it all is not a phishing scam or a supply-chain swap. It is something far more structurally alarming: a flaw in the random number generator (RNG) that underpins the security of the wallets themselves.
The warning was sounded early Monday by Alex Thorn, head of research at Galaxy Research, who flagged that the fourth coordinated attack wave is likely in motion. Thorn's characterization — "likely targeting Coldcard users" — reflects the difficulty of attribution in real time, but the pattern of the suspected fourth wave mirrors the mechanics of the three confirmed prior incidents closely enough that researchers are treating it as a continuation of the same campaign rather than a coincidence.
The RNG vulnerability is the kind of flaw that makes security professionals lose sleep. A hardware wallet's entire value proposition rests on generating private keys that are cryptographically unpredictable — keys that an adversary cannot guess or reconstruct. When the RNG responsible for producing that entropy is compromised or flawed, the private keys it generates are no longer truly random. They become, in effect, reproducible. An attacker who understands the flaw can derive the same keys the device produced, sweep the associated addresses, and disappear — all without ever physically touching the device. The victim has no warning until the balance reads zero.
Across the three confirmed waves, 4,585 addresses have been identified as compromised, and 1,367.05 BTC has been attributed to the exploit. At current market values, that figure represents a loss in the tens of millions of dollars depending on the price at time of drain. The fourth wave, if confirmed, will push both the address count and the BTC total higher. The 462 suspected new victims represent a meaningful expansion of the attack surface, and there is no structural reason to assume this wave will be the last if the underlying vulnerability has not been fully patched and disclosed across the affected device population.
What makes this episode particularly consequential for the broader hardware wallet industry is the profile of Coldcard's user base. Coldcard has long been positioned — and widely regarded — as one of the most security-conscious Bitcoin storage solutions available. It is the preferred device of technically sophisticated users, Bitcoin-only purists, and self-custody advocates who have specifically opted out of exchange custody precisely because they distrust third-party security. The irony that a device chosen for its security rigour is now the vector for a multi-wave coordinated theft campaign is not lost on the community, and it will reverberate through cold storage adoption conversations for months.
The RNG failure also raises uncomfortable questions about the auditability of hardware wallet firmware and entropy sources more broadly. Unlike software, where patches can be deployed rapidly and verified publicly, hardware security depends on physical components, secure elements, and firmware interactions that are significantly harder to audit from the outside. Users who purchased a Coldcard years ago and have not updated firmware, or who generated keys on an affected firmware version, may be sitting on compromised addresses right now without any indication that their funds are at risk. The attack waves suggest that whoever is exploiting this vulnerability is doing so methodically and at scale — scanning derived addresses in batches rather than sweeping everything at once, which could be a deliberate strategy to avoid triggering large on-chain alerts early in the campaign.
For Coldcard's manufacturer, Coinkite, the path forward demands urgent and transparent communication: a precise accounting of which firmware versions, hardware revisions, and RNG configurations are affected; clear guidance on whether funds held in addresses generated under those conditions should be moved immediately; and a credible public timeline for full remediation. Silence or ambiguity at this stage will only compound the damage, both financial and reputational.
For the self-custody community, the lesson cuts deeper than a single product's flaw. Cold storage is not synonymous with safety. Hardware is not immune to critical vulnerabilities. And when entropy fails, everything built on top of it fails with it. The 462 suspected victims now joining more than 4,500 others in a growing cohort of Coldcard losses are a concrete reminder that the security of any wallet — hardware or otherwise — is only as strong as the randomness it was built on.
Written by the editorial team — independent journalism powered by Bitcoin News.