Coldcard Loss Raises Concerns After $112 Million Bitcoin Theft

Blockonomics
BTCC


What to know:

  • Hackers stole more than 1,778 BTC worth approximately $112 million from over 5,000 Coldcard wallets.
  • The attack exploited a vulnerability linked to Coldcard firmware version 4.0.1, released in March 2021.
  • Coinkite issued a security patch and urged affected users to create new seed phrases and move their funds.

The Coldcard loss incident is arguably the biggest case of hardware wallet security breach in crypto space history, as hackers managed to steal over 1,778 bitcoins valued at about $112 million from over 5,000 wallets.

The security breach began on July 30, 2026, as a result of a loophole in the Coldcard firmware that made hackers able to exploit wallets created using compromised software.

The theft happened rather fast. In just 41 minutes, over 1,000 BTC had been stolen from over 1,000 wallets. In mid-August, about 1,531 BTC were still available in wallets owned by the hackers.

Binance

Coldcard Loss Linked to a 2021 Firmware Problem

The Coldcard loss has been attributed to the firmware version 4.0.1, which was released by Coinkite in March 2021. The bug was caused by the faulty generation of seed phrases within the Coldcard devices through the new update.

Seed phrases are essential, as they are necessary for the generation of private keys that will be used to access an individual’s cryptocurrency. The Coldcard devices are supposed to generate the seed phrases using a hardware random number generator.

This was a huge security threat because predictable randomness could compromise the generation of cryptographic keys. It is said that the flaw persisted for many years without any solution.

As stated by Galaxy Research, there had been complaints raised to Coinkite about a related problem back in May 2025. Eventually, the attackers found a way to exploit the vulnerability on a massive scale.

Several Coldcard devices were vulnerable to this attack; namely, the Mk2, Mk3, Mk4, Q, and Mk5 devices. In addition, the attackers who exploited this vulnerability were at least 12.

Also Read | Cboe SEC Approval Sought for 3x Bitcoin and Ethereum ETFs

Coinkite Issues Security Fix

The security advisory from Coinkite came out on July 30, the very same day when these attacks started. The patched firmware was ready for distribution on July 31, and Rodolfo Novak, the CEO of Coinkite, issued an apology for what had happened.

This, however, is not the solution for the users whose seed phrases had been generated by the vulnerable software.

Coinkite has suggested that the users create an entirely new seed phrase, using the patched firmware, and then move their money into the new wallet. The seed generated through vulnerable firmware is still compromised even after the firmware update today.

Coldcard Loss Raises Self-Custody Questions

A Coldcard loss shows the risks linked to cryptocurrency self-custody. Hardware wallets are designed to protect funds, but firmware vulnerabilities can cause major losses.

The Coldcard loss raises concerns about random number generation testing and security report handling in hardware wallets.

The Coldcard loss highlights the need for stronger firmware security and better vulnerability testing. For Coldcard owners, it is very important to determine whether a certain seed has been generated using the affected firmware or not.

Also Read | CLARITY Act Approval Chances Fall Sharply Ahead of Senate Return



Source link

Coinmama

Be the first to comment

Leave a Reply

Your email address will not be published.


*