Hackers exploit Coldcard firmware flaw, stealing $89 million in Bitcoin from thousands of wallets

1 hour ago 2



The whole point of a cold wallet is that it’s cold. Offline. Air-gapped. Unreachable. A vulnerability in Coldcard hardware wallets just proved that premise has an asterisk. Hackers exploited a firmware flaw in Coldcard devices produced by Canadian manufacturer Coinkite, draining approximately 1,367 BTC, valued at nearly $89 million, from 4,585 addresses across several waves of attacks beginning July 30, 2026. What actually happened The vulnerability traces back to a March 2021 firmware build affecting Coldcard Mk3 versions 4.0.1 through 4.1.9 and earlier releases. The flaw was in how those devices generated wallet seeds. Instead of routing entropy through the hardware random number generator, a bug pushed the process through a software RNG. In English: the randomness used to create your private key was far less random than advertised, making it mathematically feasible to reconstruct keys offline without ever touching the physical device. The first wave hit on July 30, 2026. Roughly 594 BTC, around $38 million at the time, was drained from approximately 500 dormant addresses in under 30 minutes. That’s not a slow, probing attack. That’s a coordinated sweep. Subsequent waves pushed t...

Read Entire Article