Tracking the Coldcard Hackers: Inside the $120M Bitcoin Theft with Alex Thorn
8/7/2026 · 69 min · transcript via whisper
Tags
Key topics
— Over $120 million in Bitcoin drained from Coldcard hardware wallets via a critical entropy bug in firmware released March 17, 2021. The attack is ongoing across multiple waves and footprints, with at least 1,600 BTC confirmed stolen from ~7,500 addresses.
— Alex Thorn (Galaxy Research) identified Wave One (1,082.65 BTC), Wave Two (76 BTC), Wave Three (293 separate attacker addresses), and multiple smaller "footprint" patterns. Wave One attacker likely identifiable via centralized RPC provider logs, per Block Inc. engineers.
— Vulnerable devices: Coldcard MK3, MK4, MK5, Q, and upgraded MK2 models. Users who generated keys on these devices after March 21, 2021 should assume compromise and migrate funds immediately—even to centralized exchanges if necessary.
— Attackers likely using AI assistance to exploit the vulnerability; multiple independent threat actors now copying the attack. Vulnerability permits seed phrase and private key derivation without access to stored keys.
— The bug stems from weak on-device entropy generation; Coldcard switched from a vetted open-source RNG to a faulty proprietary one that fell back to no entropy. Thorn characterizes this as negligence, not malice.
— Multisig and collaborative custody (Casa, Unchained, Nunchuk) emerge as the only responsible path forward for self-custody. Single-signature hardware wallet custody model is now considered too risky.
Market & price signals
— Bitcoin trading ~$64,800 at time of recording (August 5, 2024). Despite the headline hack, price remained stable—Thorn attributes this partly to long-term DCA holders (not panic sellers) and the $130 million loss being small relative to Bitcoin's total liquidity. The blast radius, even if all stolen coins dump, is unlikely to materially move the market. Institutional investors recognize the vulnerability as isolated to retail hardware wallet users, not systemic to Bitcoin itself.
Actionable insights
— Immediate action for affected users: If you generated keys on a Coldcard device (MK3/MK4/MK5/Q or upgraded MK2) after March 21, 2021, migrate funds to a new address now. Even sending to a trusted exchange (River, Coinbase) is preferable to leaving coins at risk. Verify your address history for evidence of unauthorized drains.
— Prove ownership and file reports: DM @IntangibleCoins on X with your drained addresses (no PII needed). Thorn will provide forensic reports you can file with local law enforcement, FBI IC3, and cyber crime centers. Keep your Coldcard device as cryptographic proof of ownership. Upstream KYC records (if coins came from a regulated exchange) are strong evidence of legitimate ownership for recovery purposes.
— Future self-custody strategy: Do not use single-sig hardware wallet storage. Adopt multisig setups with collaborative custody providers or, if technically capable, roll your own. This diversifies risk and prevents a single device compromise from draining all funds. Non-technical users should consider regulated custodians or dollar-cost average into Bitcoin via brokerages and ETFs until they gain sufficient confidence.
Episode sponsorships
Paid placements mentioned in this episode. BTC Pods is not sponsored by or affiliated with these advertisers. Links are included so you can find offers mentioned on the show.
— No sponsorships in this episode.