Coldcard Hardware Wallet Flaw Linked to $70 Million Bitcoin Theft in 41 Minutes
Summary
An attacker drained 1,196 Bitcoin addresses on July 30, 2026, taking 1,082.65 BTC (~$70.2M) in 41 minutes. Galaxy Research traced the sweep to a March 2021 firmware integration error in Coldcard, the Bitcoin-only hardware wallet by Canada's Coinkite.
Key Details
- Date: 2026-08-01 (disclosure) / 2026-07-30 (theft)
- Source: The Hacker News / Ars Technica
- Reliability: Tier 2/4 โ Established cyber journalism
- Affected Device: Coldcard hardware wallet (Bitcoin-only) by Coinkite (Canada)
- Root Cause: Firmware integration error from March 2021 โ seed generation routed to deterministic software PRNG instead of STM32 hardware RNG
- Impact: 1,082.65 BTC stolen (~$70.2M) from 1,196 addresses in 41 minutes
- Attribution: Unknown attacker
Technical Details
The glitch in the Coldcard firmware caused seed generation to use a deterministic software PRNG rather than the STM32 hardware random number generator. An attacker who can constrain the device UID, timer state, and RNG-call history can reproduce seeds offline without physical access by checking derived addresses against blockchain data.
Coinkite shipped emergency firmware for all models on July 31, but patching does not repair already-exposed seeds โ users must generate new seeds on patched firmware.
Related
- Hackers Poison Adform Script To Swap Crypto Wallet Addresses Across Customer Sites โ Cryptocurrency address manipulation attack