Coldcard Firmware Flaw Leads to $88 Million Bitcoin Theft

Coldcard Firmware Flaw Leads to $88 Million Bitcoin Theft

First seen 2 Aug 2026, 08:53 UTC Thehackernews247WallstNews.BitcoinTechtimesNewscord+46 69.9

Article Content

Browse articles
ThreatCluster

A significant vulnerability in Coldcard hardware wallets allowed attackers to exploit weak seed generation, resulting in the theft of approximately 1,367 BTC (around $88.6 million) from 4,585 addresses. The exploit, which began on July 30, 2026, involved a firmware flaw that bypassed the device's hardware random number generator, leading to predictable seed phrases. Initial reports indicated losses of about 594 BTC worth $38 million, but further analysis revealed the total theft was much larger. The attack was executed in multiple waves, with the first two showing similar transaction patterns, suggesting a coordinated effort. Affected users are urged to migrate their funds to new wallets, as simply updating firmware does not secure previously generated seeds. The ongoing nature of the theft has raised alarms about the security of hardware wallets and self-custody practices in the cryptocurrency space.

Key Points: • Coldcard firmware flaw led to theft of approximately 1,367 BTC (about $88.6 million). • Attackers exploited weak randomness in seed generation, affecting 4,585 addresses. • Users must create new wallet seeds to secure their funds; firmware updates alone are insufficient.

Timeline

2026-07-30
Initial theft reported
Attackers drained approximately 594 BTC from 500 wallets within 25 minutes, exploiting a firmware vulnerability.
Techtimes
2026-08-01
Loss estimates revised
Galaxy Research reported total losses from the Coldcard exploit had risen to 1,367 BTC, valued at $88.6 million.
News.Ycombinator
2026-08-02
Ongoing thefts confirmed
Researchers indicated that the thefts were still occurring, with attackers maintaining control over the stolen funds.
Decrypt.Co