Coldcard Hardware Wallet Vulnerability Linked to Bitcoin Theft Worth More Than USD 70 Million

Views: 103 views

416/69 Monday, August 3, 2026

Reports on July 30 indicated that attackers transferred Bitcoin from 1,196 addresses within 41 minutes, totaling 1,082.65 BTC, or approximately USD 70.2 million at the time of the incident. Galaxy Research analyzed the transfer pattern and linked the incident to a vulnerability in the firmware of Coldcard, a Bitcoin-only hardware wallet developed by Coinkite. The vulnerability was caused by a firmware integration error in March 2021, which caused the seed generation process to use a deterministic software pseudorandom number generator (PRNG) instead of the hardware random number generator (RNG) of the STM32 chip.

Block stated that if attackers could obtain or narrow down certain device-specific information, such as the device UID, timer state, and history of previous RNG calls, they could generate candidate output streams offline without accessing the device. The attackers could then verify candidate seeds by deriving addresses and comparing them with data on the public blockchain. Coinkite released emergency firmware for all affected models and release tracks on July 31. However, installing new firmware cannot fix seeds that were already generated on vulnerable firmware. Coinkite recommends that users with at-risk seeds generate a new seed on fixed firmware and move their coins to a new wallet, because restoring the old seed to updated firmware or another wallet still carries the same risk.

The affected models depend on the firmware used at the time the seed was created, not the version currently installed. According to available information, Mk3 versions 4.0.1 through 4.1.9 are affected and were fixed in version 4.2.0, while Block stated that Mk2 and Mk3 versions 4.0.0 through 4.1.9 are at risk. Mk4 and Mk5 are affected if they used versions before 5.6.0, Q models before 1.5.0Q, Edge Builds before 6.6.0X for Mk4/Mk5, and before 6.6.0QX for Q. Coinkite stated that seeds generated with at least 50 independent and secret dice rolls are not at risk from this vulnerability alone. However, if users are uncertain about the number of dice rolls or the privacy of the dice-rolling process, they should move assets to a new seed. At the same time, the attackers have not been identified, and there are no public reports clearly showing that a victim’s seed was reconstructed and matched to the addresses from which funds were transferred.

Source: https://thehackernews.com/2026/08/coldcard-hardware-wallet-flaw-linked-to.html