Coldcard Wallet Vulnerability Leads to $70 Million Bitcoin Theft

A firmware flaw in Coldcard hardware wallets enabled attackers to steal over 1,000 Bitcoin, valued at $70 million, from nearly 1,200 wallets by exploiting weak seed generation, according to Galaxy Research. The attackers were able to recreate private keys offline without physical access to the devices. Coldcard manufacturer Coinkite acknowledged the bug, released emergency updates, and urged users to migrate funds to new wallets.

Borsaya Newsroom
|
CoinDesk
|
August 1, 2026 at 05:55 AM
|
3 min read
|

A significant development in the cryptocurrency markets has revealed that approximately $70 million worth of Bitcoin (BTC) was stolen due to a critical software vulnerability identified in Coldcard, a prominent hardware wallet. A report by Galaxy Research indicates that this security breach stemmed from a flaw in the random number generator used by Coldcard wallets during seed phrase creation. This allowed attackers to predict private keys offline, without physical access to the devices, and drain over 1,000 BTC from roughly 1,200 addresses.

The attack unfolded rapidly on July 30, 2026, over a period of about 40-41 minutes, with the majority of funds being quickly consolidated. Coinkite, the maker of Coldcard, confirmed after the incident that a firmware bug affected Mk3 models from version 4.0.1 onwards, released in March 2021, and later extended to certain Mk4, Mk5, and Q models. This flaw caused the wallet to fall back to a weak software pseudo-random number generator (PRNG) instead of the intended hardware true random number generator (TRNG), increasing the predictability of the seed phrases. Coinkite publicly disclosed the vulnerability approximately 30 hours after the attack occurred.

This incident has intensified concerns within the cryptocurrency community, particularly among individual investors, regarding the reliability of hardware wallets and self-custody solutions. The attack reportedly targeted single-signature wallets, many of which had been dormant for years. The stolen Bitcoins were quickly consolidated into a smaller number of addresses. Such an attack demonstrates that even hardware wallets are not entirely immune to sophisticated threats, reminding users of the need for continuous vigilance.

Coinkite has taken full accountability for the bug and issued an apology to affected users. The company released emergency firmware updates for all affected models: version 4.2.0 or later for Mk3, 5.6.0 or later for Mk4 and Mk5, and 1.5.0Q or later for the Coldcard Q. However, Coinkite emphasized that updating the firmware alone does not secure existing seeds; users must generate an entirely new recovery phrase and migrate their funds to a new wallet.

This event has amplified calls for stricter scrutiny of hardware wallet manufacturers' security protocols. Analysts suggest that the development of multi-signature solutions and other mechanisms designed to mitigate single points of failure might accelerate. The price of Bitcoin experienced a slight dip following the news of the attack but managed to remain above its critical $60,000 support level, avoiding a major market crash. Nevertheless, this incident underscores once again the importance for individual crypto investors to exercise greater caution and continuously review their security practices to safeguard their assets.

Related Symbols

Share
9

₿ Want to ride this crypto move?

Open an account in minutes. Compare brokers offering crypto and start investing today — zero commission options available.

Comments (0)

0/1000

No comments yet. Be the first to comment!

Coldcard Wallet Vulnerability Leads to $70 Million Bitcoin Theft | Borsaya.com