Coldcard Wallet Firmware Flaw Leads to $70 Million Bitcoin Loss

Galaxy Research's analysis reveals a firmware flaw in Coldcard hardware wallets resulted in the theft of 1,082.65 Bitcoin, worth approximately $70 million, from 1,196 addresses. The vulnerability stemmed from weak randomness in seed phrase generation.

Borsaya Newsroom
|
Cointelegraph
|
August 1, 2026 at 09:23 AM
|
4 min read
|

A critical firmware flaw in the popular Bitcoin (BTCUSD) hardware wallet Coldcard has led to the theft of approximately $70 million worth of Bitcoin. According to a detailed analysis by crypto analytics firm Galaxy Research, a total of 1,082.65 Bitcoin was transferred from 1,196 addresses within a brief 41-minute window on July 30. This incident has reignited concerns regarding the security of hardware wallets, which are often considered the safest option for storing cryptocurrencies.

The vulnerability in Coldcard wallets, manufactured by Canadian company Coinkite, originated from a firmware build error present since March 2021 (versions like 4.0.0 or 4.0.1 for Mk3). This error caused the seed phrase generation process to default to a deterministic software pseudorandom number generator (PRNG) instead of the intended hardware random number generator (RNG). Consequently, the effective entropy was significantly reduced, for instance, from 128 bits to roughly 40 bits on Mk3 models and about 72 bits on Mk4, Mk5, and Q models. This diminished randomness made it feasible for attackers to guess or brute-force private keys offline.

Galaxy Research traced the transfers, which occurred between 1:10 a.m. and 1:51 a.m. UTC on July 30, spanning blocks 960,183 through 960,191. This timing is crucial as it was approximately 30 hours before Coldcard issued its first public security advisory, suggesting a rapid and automated execution of the attack. The attackers utilized transactions with distinctive on-chain signatures, including identical fees of 30 satoshis per virtual byte and no change outputs, to consolidate the funds. Initial estimates of the loss were around 594 BTC, valued at about $38 million, but Galaxy's analysis substantially increased this figure.

This development has significantly impacted sentiment in the cryptocurrency markets, particularly concerning self-custody solutions. While hardware wallets are widely perceived as a robust defense against centralized exchange risks, the Coldcard incident challenges this perception. Despite Bitcoin maintaining its price above the $60,000 level, market sentiment turned negative, and the fear index escalated. Changpeng Zhao (CZ), the founder of Binance, also urged wallet diversification in response to the exploit.

Coinkite acknowledged the bug, apologized to affected users, and released emergency firmware updates for all impacted models on July 31. However, the company emphasized that simply updating the firmware does not secure existing wallets generated with a vulnerable seed. Coldcard advises affected users to generate an entirely new seed phrase on a patched firmware and carefully migrate their assets to the new wallet. Restoring an old seed to updated firmware or another wallet carries the weakness forward, Coinkite warned.

Analysts warn that new attacks are likely to occur if users do not migrate their funds from affected Coldcard-generated addresses. This incident underscores the critical importance of robust entropy in seed phrase generation processes and user vigilance in managing hardware wallet security for cryptocurrency holders. The complexities of self-custody solutions and the user's responsibility for security are further highlighted by such events.

Related Symbols

Share
12

₿ Want to ride this crypto move?

Open an account in minutes. Compare brokers offering crypto and start investing today — zero commission options available.

Comments (0)

0/1000

No comments yet. Be the first to comment!

Coldcard Wallet Firmware Flaw Leads to $70 Million Bitcoin Loss | Borsaya.com