For years, hardware wallets have been regarded as one of the safest ways to store Bitcoin. But a recent theft involving nearly $38 million worth of BTC is reminding investors that even self-custody is only as secure as the technology behind it.
Security researchers are investigating a coordinated sweep of 594.48 BTC from hundreds of single-signature wallets, raising concerns that some recovery seeds may have been generated with insufficient randomness. Although no definitive cause has been identified, the incident has prompted fresh questions about the long-term security of older hardware wallet devices.
The investigation began after a Bitcoin holder reported losing funds from a wallet whose recovery seed had originally been generated on a Coldcard Mk3 hardware wallet purchased in 2021. The same seed was later restored onto a newer device in 2026, but researchers have yet to determine whether that sequence of events played any role in the theft.
Blockchain data analyzed by AnchorWatch CEO Rob Hamilton revealed that more than 1,300 unspent transaction outputs (UTXOs) were swept through roughly 500 transactions within only three Bitcoin blocks. The stolen coins, worth approximately $38.3 million at the time, were ultimately consolidated into a single address, suggesting a carefully planned operation rather than random attacks.
Researchers suspect the attackers may have exploited wallets created with weak cryptographic entropy. Instead of attempting to crack every possible wallet, they may have focused on a small subset of recovery seeds that were easier to predict because of flawed random-number generation.
Wizardsardine CEO Kevin Loaec believes the vulnerability could stem from a low-entropy random-number generator found in a software component, secure element, manufacturing batch, or specific firmware version. If that theory proves correct, an attacker could reconstruct vulnerable wallet seeds far more efficiently than through conventional brute-force methods.
Loaec also suggested that automated tools, potentially enhanced with artificial intelligence, may have been used to identify affected wallets while limiting searches to selected BIP-84 derivation paths. Such an approach could explain why most compromised addresses were native SegWit wallets and why some victims lost only part of their holdings. However, he emphasized that this remains a working hypothesis rather than a confirmed explanation.
As investigators continue searching for answers, Canadian hardware wallet manufacturer Coinkite has advised users of Coldcard Mk3 devices running firmware versions 4.0.1 through 5.0.3 to migrate their funds as a precaution. According to the company, newer Coldcard models—including the Mk4, Mk5, and Coldcard Q—are not believed to be affected.
For Bitcoin holders, the incident highlights an often-overlooked reality of self-custody: hardware wallets significantly reduce many security risks, but they cannot eliminate them entirely. Firmware quality, secure seed generation, regular security updates, and cautious operational practices remain essential to protecting digital assets.
Until the investigation reaches a definitive conclusion, security experts recommend that users with potentially affected devices generate a new recovery seed on trusted hardware, verify the backup, perform a small test transaction, and only then transfer the remainder of their funds. For long-term Bitcoin investors, the cost of preventive action is small compared with the potential consequences of losing access to an entire portfolio.