Table of Contents

Table of Contents

Blogs

Coldcard Bug Drains $70M as Coinkite Rolls Out Urgent Fix

Weak Seed Generation Exposes 1,196 Coldcard Wallets

Galaxy Research revealed on Friday, July 31, 2026, that an attacker drained 1,082.65 BTC , worth approximately $70.2 million, from 1,196 addresses linked to Coldcard hardware wallets between 01:10 and 01:51 UTC on July 30. The theft, disclosed in a report shared on social media, stemmed from a firmware flaw in devices made by Canadian manufacturer Coinkite, caused by weak randomness in Coldcard firmware versions 4.0.0 through 4.2.0 that made wallet seeds potentially predictable for any seed generated since March 2021.

Attacker Recreates Private Keys Without Touching Devices

Coinkite said the affected Mk3 seeds carried roughly 40 bits of entropy instead of the intended 128, allowing an attacker to recreate likely private keys entirely offline without ever accessing a victim's physical device. Galaxy Research warned that further attacks remain possible on any address generated by vulnerable Coldcard firmware, noting the pattern only identifies a single attacker rather than the underlying exploit itself.

Coinkite Issues Emergency Firmware to Stop Coldcard Exploit

Coinkite released emergency firmware updates for all affected models, including version 4.2.0 or later for Mk3, 5.6.0 or later for Mk4 and Mk5, and 1.5.0Q or later for the Coldcard Q, removing the vulnerable fallback path. The company urged users to update firmware, generate a new seed, and test transactions before moving significant funds, while keeping old seeds as backup during migration.

The incident may erode confidence in hardware wallet self-custody broadly, potentially prompting users to reassess seed-generation practices across multiple device brands. With Coinkite CEO Rodolfo Novak accepting full responsibility, the case could push the industry toward stricter entropy auditing standards for hardware wallet firmware.

Galaxy Research cautioned that its analysis may not be complete, describing it as a best-effort attempt to scope the initial impact as investigators continue tracing onchain activity.

Related Post

Leave a Reply

Your email address will not be published. Required fields are marked *