Skip to content
Attackers Exploit Coldcard Firmware Flaw, Draining 1082.65 BTC From 1196 Wallets

Attackers Exploit Coldcard Firmware Flaw, Draining 1082.65 BTC From 1196 Wallets

Newscord August 1, 2026

Every outlet we compared, the headline it ran, and a link to the original article.

Coldcard's $38 million (so far) exploit shakes faith in self-custody, may push investors to ETFs

All Coldcard’s $38M Mk3 exploit and what’s for Bitcoin self-custody

Coldcard Bug Exposes The New Reality: AI Is Auditing Every Open-Source Wallet

Coldcard Exploit Losses Top $70 Million As Key-generation Flaw Drains 1,000 BTC

Coldcard exploit reignites Bitcoin self-custody debate after $38 million theft

Coldcard Security Notice Puts Bitcoin Wallet Entropy Risk Back In Focus

594 BTC Gone in 25 Minutes: The Coldcard Flaw That Made Seed Phrases Guessable

Coldcard Mk3 Seed Vulnerability Sparks Urgent Migration Amid 594 BTC Theft Probe

Coldcard Hardware Wallet Hacked via Firmware Bug That Bypassed RNG for Five Years

A Coldcard hardware-wallet firmware flaw allowed attackers to recreate wallet recovery phrases and steal bitcoin from what users believed were securely self-custodied wallets, with the theft reaching 594 BTC worth roughly $ 38 million from around 500 Bitcoin wallets within 15–25 minutes.

“ Between 01:31 and 01:56 UTC on Friday 31 July 2026 ”

CryptoTicker said the sweep occurred between 01:31 and 01:56 UTC on Friday 31 July 2026, when an attacker swept funds out of around 500 separate Bitcoin wallets and moved more than 1,300 individual UTXOs across 500 transactions inside a three-block window.

Tech Times tied the root cause to a firmware integration error that bypassed the device’s dedicated random number generator for five years, saying the firmware had been silently bypassing its own dedicated random number generator since March 2021.

Bitcoin World said losses from an attack exploiting a key-generation flaw in Coldcard hardware wallets surpassed $ 70 million , draining approximately 1,000 Bitcoin from roughly 1,200 addresses, and said Coldcard released patches and urged users to update their firmware.

Bitcoin Magazine said Coldcard MK3 devices with firmware version 4.0.1 (March 2021) through 4.1.9 were the worst affected, and that 12- or 24-word seeds generated by the device that did not include user-generated dice rolls or a BIP 39 extra passphrase were vulnerable.

Coinkite CEO NVK told affected users, "If you generated a seed using a Coldcard wallet, move your funds now, using our updated best practices, before reading further," and said the fix protects new seeds going forward but does not fix seeds already generated on vulnerable firmware.

Bitcoin Magazine reported that Coinkite’s advisory was updated with specific firmware requirements, including that " Mk4 and Mk5 users must update to version 5.6.0 or later " and that "Q users must update to version 1.5.0Q or later."

Bitcoin Magazine also quoted Coinkite’s guidance that "Updating the firmware does not change or repair an existing seed," and said after updating, a new wallet needs to be created and funds sent onchain to new addresses.

CoinDesk quoted Bitcoin commentator Guy Swann saying, "This is the worst hit in bitcoin history to the most knowledgeable and 'properly secured' bitcoiners," and described the incident as thousands of individuals having their personal private keys recreated out from underneath them.

Casa CEO Nick Neuman criticized the recommended security approach, saying, "You just can't ask people to roll dice to be secure with your self custody," and added, "It's a non-starter for 99% of people."

The incident is prompting a debate over whether self-custody has become too risky for everyday investors, with CoinDesk noting that affected users must generate entirely new wallets and move their funds because updating the firmware alone does not eliminate the risk.

“ move their funds because updating the firmware alone doesn't eliminate the risk ”

Blockaid co-founder and CEO Ido Ben-Natan said the exposure originated at the key generation stage, and warned that "A hardware wallet's security ultimately comes down to the firmware and systems users interact with but never see."

Coindesk and others said the fallout may accelerate adoption of regulated custodians and spot Bitcoin ETFs, and CoinDesk quoted David Lawrence saying incidents like Coldcard’s are likely to push new investors toward regulated products such as BlackRock's iShares Bitcoin Trust (IBIT).

Tech Times said Coinkite and Block state that Mk4, Q, and Mk5 devices are "not affected" by the active exploit, while also describing how the confirmed vulnerable window covered Coldcard Mk2 and Mk3 devices that generated a wallet seed using firmware v4.0.0 through v5.0.3.

Bitcoin World framed the broader consequence as a growing concern that even hardware wallets are not immune to sophisticated attacks, while saying users who suspect they may be affected should immediately transfer funds to a newly generated wallet using updated firmware.

How victims, perpetrators and terms are handled across outlets.

Get every Crypto story like this one, in one email

Daily or weekly, only the topics you follow, each with the difference our analysis found across the outlets covering it.

Russia Bans Cryptocurrency Mining in Moscow, Moscow Region, and Kursk Through 2032

Bank of Italy Study Finds Stablecoin Remittances Show No Systematic Cost Advantage

Thom Tillis and Ruben Gallego Send CLARITY Act Ethics Revision to White House

Chuck Schumer Unveils Anti-Corruption Bureau Bill Targeting Trump’s Crypto Self-Dealing

Extracted Entities

Attack Types (1)

Companies (1)

Countries (2)