Close Menu
  • Markets
    • Spot Market
      • Market Overview
      • Top Gainers / Losers
      • Market Cap Charts
      • Reviews
    • Futures Market
      • Market Overview
      • Funding Rate
      • Liquidations
      • Long Short/Ratio
  • Metrics
    • Dashboard
    • Whale tracker
    • Market Heatmap
    • Funding Rates
  • News
    • Bitcoin
    • Ethereum
    • Altcoins
  • Prediction
  • Opinion
  • Calendar
  • Live Feed
What's Hot

Putin: Ukraine Strikes Opened “Pandora’s Box”, Rejects Peace

August 22, 2026

Bitcoin Surges Past $79K Amid Jump Crypto Sell-off

August 22, 2026

Bitcoin, Ether ETFs See $2.6B Inflows, Volume Triples

August 22, 2026

ZachXBT Names Canada Worst Global Hotspot for Crypto Fraud

August 22, 2026

Amazon Increases Prices on Devices Due to Chip Demand

August 22, 2026

Bitcoin validation needs 17 GPU years compute power

August 22, 2026

Social Security 2027 COLA Projection Drops to 3.6%

August 22, 2026

Tariff Refunds Erase $100 Billion Revenue, Causing Irreversible Damage

August 22, 2026

Mark Carney: Canada Declares ‘War’ on US Over Trade

August 22, 2026

Peter Manning New York Files Chapter 11 Bankruptcy

August 22, 2026
Facebook X (Twitter) Instagram
Daily Crypto News
  • Markets
    • Spot Market
      • Market Overview
      • Top Gainers / Losers
      • Market Cap Charts
      • Reviews
    • Futures Market
      • Market Overview
      • Funding Rate
      • Liquidations
      • Long Short/Ratio
  • Metrics
    • Dashboard
    • Whale tracker
    • Market Heatmap
    • Funding Rates
  • News
    • Bitcoin
    • Ethereum
    • Altcoins
  • Prediction
  • Opinion
  • Calendar
  • Live Feed
Dashboard
Daily Crypto News
Home»Bitcoin»Coldcard firmware flaw allows $70.2 million Bitcoin theft from 1,196 wallets
Coldcard wallet flaw: Coldcard firmware flaw allows $70.2 million Bitcoin theft from 1,196 wallets
A critical firmware flaw in Coldcard hardware wallets has led to the theft of 1,082.65 Bitcoin, valued at $70.2 million, from users.
Bitcoin

Coldcard firmware flaw allows $70.2 million Bitcoin theft from 1,196 wallets

Michael FawnBy Michael FawnAugust 2, 20265 Mins Read
Share
Facebook Twitter LinkedIn Pinterest Email

A significant vulnerability within Coldcard hardware wallets, manufactured by Canadian firm Coinkite, led to the theft of 1,082.65 Bitcoin, worth approximately $70.2 million, on July 30, 2026. This extensive incident saw funds drained from 1,196 Bitcoin addresses in a rapid 41-minute period, highlighting a critical Coldcard wallet flaw.

The core issue stemmed from a firmware flaw that compromised the randomness of seed generation, making private keys guessable for affected users. Coinkite has taken full accountability for the bug, issuing an apology and releasing urgent firmware updates to mitigate further risks.

Firmware Flaw Exploited in Rapid Theft

The theft on July 30, 2026, was a direct consequence of a coding error introduced in March 2021 with Coldcard firmware version 4.0.0 or 4.0.1. Instead of using the robust hardware random number generator (RNG), seed generation inadvertently defaulted to a predictable software pseudorandom number generator (PRNG).

This critical oversight meant that the entropy, or true randomness, of the generated seeds was severely limited. For example, Mk3 models effectively had around 40 bits of entropy, while Mk4, Mk5, and Q models had about 72 bits, far below the expected 128 bits for a secure 12-word BIP-39 seed.

The technical breakdown of the vulnerability

The vulnerability traced back to the MICROPY_HW_ENABLE_RNG macro, which was incorrectly defined as zero in Coldcard’s production configuration. The libngu library, responsible for seed generation, checked only for the macro’s existence, not its enablement state.

Consequently, the system bound itself to MicroPython’s Yasmarang fallback. This fallback mechanism was initialized using easily determinable device unique IDs and timer registers, crucially collecting no fresh entropy after its initial setup, making it highly susceptible to prediction.

Attackers could determine or sufficiently constrain device unique IDs, timer states, and past RNG call histories. This allowed them to reproduce candidate seed output streams offline without ever needing physical access to a Coldcard device.

They would then derive potential Bitcoin addresses from these candidate seeds and cross-reference them against public blockchain data. This method enabled the attacker to pinpoint and drain vulnerable single-signature wallets, many of which held more than 0.15 BTC and had remained dormant for years.

Coinkite’s Response and Broader Implications

Rodolfo Novak (NVK), CEO of Coinkite, quickly apologized and confirmed the company’s full accountability for the firmware bug. Coinkite responded on July 31, 2026, by shipping emergency firmware for all affected models and release tracks.

Users of Mk2/Mk3 devices were advised to update to version 4.2.0 or later, while updates for Mk4, Mk5, and Q models were also provided. This swift action aims to prevent further exploitation of the randomness flaw.

Attacker’s footprint and investigation

The attacker’s operations left a distinct on-chain pattern, identified by Galaxy Research, which mapped the sweep of 1,196 Bitcoin addresses. Clay Garrett, an engineer at payments company Block, further traced the attacker’s activities.

Garrett noted that the operator used a paid account at a “well-known blockchain-services provider” to query source addresses and facilitate the sweeps. The attacker’s transactions featured a characteristic fingerprint, including 30 sat/vB fees and no change outputs.

This detailed forensic work helped investigators understand the scope and methodology of the attack. It highlights the increasing sophistication of on-chain analysis in tracing illicit activities, even as attackers attempt to remain anonymous.

Repercussions for Hardware Wallet Security

This incident has sent ripples through the cryptocurrency community, forcing a critical re-evaluation of trust in hardware wallets, even those with a strong reputation like Coldcard. It underscores that even highly-regarded devices are not immune to fundamental cryptographic vulnerabilities.

Changpeng Zhao (CZ), founder and former CEO of Binance exchange, commented on the situation, stating that “Even hardware wallets can have bugs.” His observation highlights the continuous need for vigilance and robust security practices, regardless of a product’s established history.

Lessons from a compromised randomness

The Coldcard incident is a stark reminder that the security of cryptographic assets hinges on truly random number generation. When the source of randomness is compromised, the entire security model collapses, leaving funds vulnerable to sophisticated, remote attacks.

This event emphasizes the importance of independent code audits and rigorous testing, especially for critical components like seed generation. It also brings into focus the challenges in maintaining security over complex software and hardware integrations.

For users, this means understanding that a hardware wallet is only as secure as its underlying firmware and its ability to generate unpredictable keys. The incident serves as a call for both manufacturers and users to prioritize transparency and continuous security verification.

Protecting Assets After the Coldcard Incident

For Coldcard users who generated seeds on affected firmware versions (4.0.0 through 4.1.9 for Mk2/Mk3, and similar for Mk4, Mk5, and Q before emergency updates), immediate action is crucial. Updating to the latest emergency firmware is the first step.

However, simply updating firmware won’t secure previously compromised seeds. Users who generated seeds during the vulnerable period should transfer their Bitcoin to a new wallet address derived from a newly generated, secure seed. This ensures their funds are protected against potential future exploits.

The incident also reinforces the value of multi-signature wallets, which require multiple private keys to authorize a transaction. While more complex to set up, these offer a significantly higher level of security against single points of failure like the Coldcard flaw.

As the cryptocurrency ecosystem matures, these events serve as powerful, if costly, lessons. They drive improvements in security protocols and reinforce the critical importance of due diligence, both from manufacturers developing these tools and from individuals trusting them with their digital wealth.

bitcoin theft coinkite coldcard wallet flaw hardware wallet security seed generation vulnerability
Share. Facebook Twitter Pinterest LinkedIn Tumblr Email

Related Posts

Bitcoin, Ethereum ETFs attract $825.8M as institutional demand returns

August 22, 2026

Mark Connors projects $180,000 Bitcoin as Treasury buybacks shift macro outlook

August 21, 2026

Can Proof of Work Be Sustainable? The Environmental Reality of Bitcoin Mining

August 20, 2026

Bitcoin climbs past $69,000 as Bitcoin Treasury buyback forces yields lower

August 20, 2026

Recent Posts

  • Putin: Ukraine Strikes Opened “Pandora’s Box”, Rejects Peace
  • Bitcoin Surges Past $79K Amid Jump Crypto Sell-off
  • Bitcoin, Ether ETFs See $2.6B Inflows, Volume Triples
  • ZachXBT Names Canada Worst Global Hotspot for Crypto Fraud
  • Amazon Increases Prices on Devices Due to Chip Demand
Top Posts

Bitcoin, Ethereum ETFs attract $825.8M as institutional demand returns

August 22, 2026

Mark Connors projects $180,000 Bitcoin as Treasury buybacks shift macro outlook

August 21, 2026

Can Proof of Work Be Sustainable? The Environmental Reality of Bitcoin Mining

August 20, 2026

Stay updated with the latest crypto news, market trends, and expert insights. We provide accurate and timely information to help you make better decisions.

Facebook X (Twitter) Instagram Pinterest YouTube
Our Resources
  • About Us
  • Privacy Policy
  • Editorial Policy
  • Legal Disclaimer
  • Contact us
Categories
  • Altcoins
  • Prediction
  • Opinion
  • Guides
  • Reviews
  • Bitcoin
  • Ethereum
Recent Posts
  • Putin: Ukraine Strikes Opened “Pandora’s Box”, Rejects Peace
  • Bitcoin Surges Past $79K Amid Jump Crypto Sell-off
  • Bitcoin, Ether ETFs See $2.6B Inflows, Volume Triples
  • ZachXBT Names Canada Worst Global Hotspot for Crypto Fraud
© 2026 Daily Crypto News

Type above and press Enter to search. Press Esc to cancel.