A Coldcard firmware flaw let hackers drain $70 million in Bitcoin in 41 minutes, with losses now topping $88 million
A flaw in Coldcard's firmware has put the spotlight on a basic part of wallet security: how the device generates its seed in the first place. The issue came into focus after an attacker drained 1,196 Bitcoin addresses on July 30 in a 41-minute stretch, taking 1,082.65 BTC worth about... Read Entire Article
A flaw in the firmware of Coldcard hardware wallets enabled hackers to drain $70 million in Bitcoin within 41 minutes in July 2026. This issue was traced back to a firmware integration error in March 2021, where Coldcard devices switched from using a hardware random number generator to a deterministic software pseudorandom number generator during seed generation.
This allowed attackers to guess supposedly random seed phrases without physical access, phishing, or malware. Galaxy Research reported four waves of theft, totaling 1,367.05 BTC, worth about $88.6 million, across 4,585 addresses. Coinkite, the manufacturer of Coldcard, released an emergency firmware update to fix the vulnerability, urging users to generate new seeds on the patched firmware and move their coins.
The flaw primarily affected Coldcard Mk3 versions 4.0.0 through 4.1.9, but newer models were also vulnerable until 5.6.0 and later edge-specific fixes.
Written by urgent.news from TechSpot's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.
Also reported by 3 other outlets
- Bitcoin hardware wallet maker destroys some inventory after more than $88 million stolen therecord.media
- Coldcard’s 5-year flaw reveals hardware wallet testing gap: Kraken’s security chief cointelegraph.com
- Solo Bitcoin miner nets $200,000 as Coldcard hardware wallet drains rocks sentiment coindesk.com
