Develeap
Coldcard Wallets Compromised, $70.2 Million Bitcoin Stolen
Ask AI about this cluster
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.
Cluster AI
Ask questions about this threat cluster with AI-powered analysis.
Get Researcher $29.99/moArticle Content
On July 30, 2026, a firmware integration error in Coldcard hardware wallets allowed attackers to exploit a deterministic software PRNG for seed generation. This vulnerability enabled the theft of 1,082.65 BTC (approximately $70.2 million) from 1,196 Bitcoin addresses within 41 minutes. The flaw originated from a March 2021 firmware update that incorrectly routed seed generation, compromising wallet security. Users of Coldcard wallets are now at risk of losing their funds due to this critical vulnerability. The incident highlights the importance of hardware security and the potential consequences of software flaws in cryptocurrency management.
Key Points: • A firmware error in Coldcard wallets led to the theft of over $70 million in Bitcoin. • The vulnerability was due to a deterministic software PRNG used for seed generation. • 1,196 Bitcoin addresses were compromised within a short timeframe of 41 minutes.