Galaxy Digital Pins Coldcard Entropy Bug at $70M, 594 BTC Swept in 41 Minutes
On-chain forensics show a Coldcard firmware flaw cut seed entropy to 72 bits, letting attackers drain 594 BTC from ~500 wallets in six blocks.

Galaxy Digital’s research desk has put a dollar figure on the Coldcard entropy exploit: roughly $70 million in bitcoin, or 594 BTC, drained from around 500 single-signature addresses in a firmware-driven seed-generation failure. On-chain forensics from the firm show the bulk of that value moved in under an hour, a detail that changes how urgently affected holders need to act.
Six blocks, 41 minutes, no institutional footprint
Galaxy’s analysis, cited by The Daily Hodl, describes the sweep as spanning six blocks and 41 minutes, with three intervening blocks showing no sweep activity at all — a pattern the firm says implies transactions were broadcast in discrete batches rather than as a continuous stream. Galaxy cautioned its scoping “may not be complete” but called it a best-efforts attempt to size the initial impact.
The distribution of losses is notable for traders reading wallet-flow data: sub-1 BTC addresses dominate by count, while 1-50 BTC addresses account for most of the value stolen. Galaxy described that profile as characteristic of individual self-custody rather than exchange or institutional cold storage, meaning the exposure sits almost entirely with retail-scale holders running their own keys.
Entropy cut from 128 bits to 72 bits
The root cause, corroborated across incident notes reported by NewsBTC, was a firmware bug in which the intended hardware random number generator was replaced by a predictable software fallback during seed creation, reducing entropy from 128 bits to 72 bits. That collapse narrows the effective search space for an attacker trying to reconstruct a wallet’s recovery phrase, turning what should be a computationally impossible brute force into something feasible.
Affected firmware spans Coldcard Mk3 versions 4.0.1 through 5.0.3, Mk4 and Mk5 devices prior to 5.6.0, and the Coldcard Q prior to 1.5.0Q. Seeds generated using a BIP-39 passphrase or at least 50 dice rolls are not considered at risk under the validated incident notes, since those methods add entropy outside the compromised hardware path.
Coinkite ships fixes, but old seeds stay exposed
Coinkite, the maker of Coldcard, said it takes full accountability for the bug and has apologized to affected users. The company has pushed emergency firmware: 4.2.0 or later for Mk3, 5.6.0 or later for Mk4 and Mk5, and 1.5.0Q or later for the Q, all of which strip out the vulnerable software fallback and restore reliance on the intended hardware RNG.
Critically, patching firmware does not retroactively secure a seed generated before the update. Coinkite and both reports stress that anyone who generated a wallet on affected firmware must create an entirely new recovery phrase under the fixed firmware and migrate funds — leaving the old, potentially compromised addresses drained of value rather than simply locked down.
For traders and analysts tracking self-custody risk, the concentration of losses in single-signature wallets is the structural takeaway: multisig setups, passphrase-hardened seeds and dice-based entropy generation all sat outside the blast radius, reinforcing why serious custody stacks increasingly layer more than one hardware-RNG dependency.
Read more: Coldcard Entropy Flaw Linked to 594 BTC Swept From ~500 Single-Sig Wallets