A firmware vulnerability dating back to 2021 allowed attackers to reproduce recovery seeds, triggering one of the largest self-custody failures in Bitcoin history. A firmware vulnerability present in Coldcard devices since March 2021 has been exploited to drain approximately 1,367 BTC, worth roughly $88.6 million to $89 million, from more than 4,500 wallets. It targeted the randomness used to generate recovery seeds, making them predictable enough for an attacker to reproduce offline. How the exploit workedThe vulnerability existed in Coldcard firmware versions 4.0.0 through 5.0.3. The fallout for self-custodyCoinkite, the company behind Coldcard, has urged all affected users to generate new recovery seeds on updated firmware.