Coldcard Wallets Compromised, $70.2 Million Bitcoin Stolen

Coldcard Wallets Compromised, $70.2 Million Bitcoin Stolen

First seen 2 Aug 2026, 08:53 UTC ThehackernewsDeveleap 80% similarity 66.0

Article Content

Browse articles
ThreatCluster

On July 30, 2026, a firmware integration error in Coldcard hardware wallets allowed attackers to exploit a deterministic software PRNG for seed generation. This vulnerability enabled the theft of 1,082.65 BTC (approximately $70.2 million) from 1,196 Bitcoin addresses within 41 minutes. The flaw originated from a March 2021 firmware update that incorrectly routed seed generation, compromising wallet security. Users of Coldcard wallets are now at risk of losing their funds due to this critical vulnerability. The incident highlights the importance of hardware security and the potential consequences of software flaws in cryptocurrency management.

Key Points: • A firmware error in Coldcard wallets led to the theft of over $70 million in Bitcoin. • The vulnerability was due to a deterministic software PRNG used for seed generation. • 1,196 Bitcoin addresses were compromised within a short timeframe of 41 minutes.

ThreatCluster AI How this analysis works

Timeline

2021-03-01
Firmware integration error introduced
A firmware update incorrectly routed seed generation to a software PRNG instead of hardware randomness.
Develeap
2026-07-30
Massive Bitcoin theft occurs
Attackers exploited the firmware flaw to drain 1,196 Bitcoin addresses, stealing 1,082.65 BTC in just 41 minutes.
Develeap

Community

Browse all →

Tracked Entities in This Story