Newscord Coldcard Firmware Flaw Leads to $88 Million Bitcoin Theft
Article Content
- •Coldcard firmware flaw led to theft of approximately 1,367 BTC (about $88.6 million).
- •Attackers exploited weak randomness in seed generation, affecting 4,585 addresses.
- •Users must create new wallet seeds to secure their funds; firmware updates alone are insufficient.
A significant vulnerability in Coldcard hardware wallets allowed attackers to exploit weak seed generation, resulting in the theft of approximately 1,367 BTC (around $88.6 million) from 4,585 addresses. The exploit, which began on July 30, 2026, involved a firmware flaw that bypassed the device's hardware random number generator, leading to predictable seed phrases. Initial reports indicated losses of about 594 BTC worth $38 million, but further analysis revealed the total theft was much larger. The attack was executed in multiple waves, with the first two showing similar transaction patterns, suggesting a coordinated effort. Affected users are urged to migrate their funds to new wallets, as simply updating firmware does not secure previously generated seeds. The ongoing nature of the theft has raised alarms about the security of hardware wallets and self-custody practices in the cryptocurrency space.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (87)
Following this threat?
Track CornFlake RAT and Block in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Critical WSO2 API Manager Vulnerability Under Active Exploitation A critical vulnerability (CVE-2026-5430) in WSO2 API Manager is being actively exploited, allowing unauthenticated attackers to forge admin tokens via JWT authentication bypass. This flaw, which has a CVSS score of 10.0, affects multiple WSO2 products including API Manager, Universal Gateway, Traffic Manager, and API…
Critical Linux Kernel Vulnerability CVE-2025-39682 Under Active Exploitation A critical vulnerability (CVE-2025-39682) in the Linux kernel allows remote code execution through mishandling of zero-length TLS records. This flaw affects kTLS-enabled hosts running vulnerable kernel versions, exposing them to attackers without authentication. CISA added this vulnerability to its Known Exploited…