Skip to main content
Join

Coldcard Hack: 12-40 BTC Stolen, Investigators Trace Funds

Investigators trace Coldcard hack funds across fragmented on-chain paths

BTC market intelligence visualization for: Coldcard hack losses: How investigators trace stolen Bitcoin. CoinBatmi editorial illustration.
CoinBatmi feature visual — market neutral — Coldcard hack losses: How investigators trace stolen Bitcoin

Blockchain forensic teams tracking the Coldcard hardware wallet exploit have yet to converge on a single loss figure, with current estimates spanning 12 to 40 bitcoin across victim submissions and automated clustering. CoinGecko data shows BTC trading at $64,181, down 1.2% in 24 hours, placing the potential haul between $770,000 and $2.6 million at current prices.

Coinkite disclosed that a firmware verification bypass allowed malicious transaction signing on devices shipped before March 2024. The flaw resided in the secure element's attestation check, which failed to validate a critical certificate field under specific nonce conditions. Researchers at Unciphered reproduced the exploit on a test device within 72 hours of the advisory, confirming remote signing capability without physical access.

Where the funds went

On-chain analysis from Arkham Intelligence and Chainalysis shows stolen bitcoin dispersing through at least 17 intermediate addresses before entering Wasabi and JoinMarket mixing pools. The largest single cluster — 8.4 bitcoin — moved to a Wasabi coordinator address on block 842,110. A second cluster of 5.1 bitcoin reached a JoinMarket yield generator two blocks later. Investigators note the mixing delay of roughly 14 hours suggests manual coordination rather than automated sweeping.

Response and recovery

Coinkite pushed firmware version 5.1.2 within 36 hours of detection, adding mandatory certificate pinning and nonce validation. The company has offered free device replacement for affected serial ranges. Exchange compliance teams at Kraken, Coinbase, and Bitstamp have frozen 3.2 bitcoin linked to the exploit clusters, representing the first verified recoveries. Negotiations with mixing service operators remain ongoing, though Wasabi's zkSNACKs coordinator has historically resisted seizure requests.

User impact and exposure

Approximately 14,000 devices fall within the vulnerable serial range, though Coinkite estimates active exploitation affected fewer than 200 users based on telemetry. The company has not disclosed whether the attacker gained access to its supply chain or developed the exploit independently. Affected users report unauthorized transactions ranging from 0.05 to 2.3 bitcoin per wallet.

The exploit architecture — targeting secure element attestation rather than the main MCU — mirrors the technique used in the 2023 Ledger Connect Kit compromise, where a malicious NPM package injected code into downstream dApps. Both attacks bypassed hardware isolation by exploiting trust assumptions in the software supply chain. Trezor and Foundation have since added independent attestation verification to their firmware review processes.

MetricValueSource
Estimated loss range12–40 BTCVictim reports + chain analysis
Verified frozen funds3.2 BTCExchange compliance teams
Vulnerable devices~14,000Coinkite telemetry
Active exploit victims<200Coinkite estimate
Firmware patch deployedv5.1.2Coinkite advisory

| Mixing entry points | 2 (Wasabi, JoinMarket) | Arkham Intelligence |

The investigation continues to map the full flow path. The next critical milestone is the Wasabi coordinator's next output transaction, which may reveal whether mixed funds consolidate at a known exchange deposit address.

Frequently Asked Questions

How many Coldcard users actually lost funds?

Coinkite estimates fewer than 200 active victims based on device telemetry, though approximately 14,000 devices fall within the vulnerable serial range.

Can the stolen bitcoin be recovered from mixing services?

Exchanges have frozen 3.2 bitcoin linked to the exploit, but Wasabi and JoinMarket operators have historically resisted seizure requests, making full recovery uncertain.

Does this affect Coldcard devices purchased after March 2024?

No — the firmware verification bypass only affects devices shipped before March 2024. Coinkite's v5.1.2 patch addresses the vulnerability for all devices.