Bitcoin self-custody at risk after Coldcard exploit drains over $83 million

1 hour ago 1



A firmware vulnerability in Coldcard hardware wallets has resulted in the theft of over 1,300 BTC, worth roughly $83 million at the time of the attacks, making it one of the largest self-custody security failures in Bitcoin’s history. The flaw, which affected firmware versions 4.0.1 through 4.1.9, caused the wallets to generate recovery seeds with approximately 40 bits of entropy instead of the intended 128 bits. In English: the wallets were supposed to create passwords so complex that guessing them would take longer than the age of the universe. Instead, they created passwords weak enough to crack remotely. No physical access to the device required. How a 2021 code regression became a 2026 disaster The vulnerability traces back to a code regression introduced in March 2021 within Coldcard MK3 devices manufactured by Coinkite. Reports of the exploit began surfacing publicly in late July 2026. The thefts rolled out in multiple waves across thousands of addresses, suggesting a systematic operation rather than opportunistic attacks. Total reported losses have climbed as high as $89 million as additional victims have come forward. Coinkite responded with a firmware update, versions 4.2...

Read Entire Article