Coldcard Wallet Exploit Steals 1,778 BTC Worth $112M

iconCryptoBriefing
Share
AI summary iconSummary
A DeFi exploit in Coldcard firmware led to the theft of 1,778 BTC, valued at $112 million, from over 5,000 addresses. The BTC update flaw, introduced in a 2021 firmware version, was exploited starting July 30, 2026. Coinkite released a patched BTC update by July 31. Users are urged to generate new seed phrases on the updated firmware to secure funds.

Hardware wallet maker Coinkite is facing the fallout from what is shaping up to be the largest hardware wallet breach on record, after a vulnerability in Coldcard firmware allowed attackers to drain more than 1,778 Bitcoin, worth roughly $112M at prevailing prices, from over 5,000 addresses.

The theft began on July 30, 2026. Within 41 minutes, attackers had swept more than 1,000 BTC from over 1,000 addresses. As of mid-August 2026, approximately 1,531 BTC remained sitting untouched in wallets controlled by the attackers.

A bug that was hiding in plain sight since 2021

The root cause traces back to a firmware update Coinkite shipped in March 2021, version 4.0.1. That update introduced a flaw in the seed phrase generation process, the step where a hardware wallet creates the master key that controls all funds stored on it.

Advertisement

Instead of pulling randomness from the device’s dedicated hardware random number generator, the flawed code rerouted that process to a software-based pseudorandom number generator. The difference matters enormously: a software PRNG is far more predictable than its hardware counterpart, and predictable randomness in cryptography is essentially an open door.

A developer flagged a related issue to Coinkite as early as May 2025, according to research from Galaxy Research. The vulnerability apparently went unpatched long enough for attackers to develop and deploy tooling that exploited it at scale, hitting multiple Coldcard models including Mk2, Mk3, Mk4, Q, and Mk5.

Galaxy Research confirmed that at least a dozen distinct attackers were involved, all exploiting the same underlying weakness.

Coinkite’s response and what users need to do

Coinkite issued a security advisory on July 30, the same day the attacks started. By July 31, patched firmware was available for affected models. CEO Rodolfo Novak offered a public apology for the breach.

The critical detail for anyone who owns a Coldcard: a firmware update alone is not enough. Because the flaw corrupted seed generation at the point of wallet creation, any seed phrase generated on a vulnerable firmware version is compromised regardless of what firmware the device runs now. Coinkite’s guidance requires affected users to generate entirely new seed phrases on patched firmware and move all funds to the new wallets immediately.

What this means for the self-custody debate

The crypto industry has spent years making the case that self-custody is safer than trusting a centralized exchange. But the Coldcard breach complicates that narrative in a specific way: when a hardware wallet is hacked at the firmware level, the user is the last line of defense, and they often do not know there is a problem until the funds are gone.

A bug introduced in 2021, flagged in 2025, and weaponized in 2026 is not a comfortable timeline for an industry that markets hardware wallets as the gold standard of security. The question competitors will face from consumers and security researchers alike is straightforward: how do you verify that your RNG implementation is actually using hardware entropy, and how quickly can you push a verified patch when it is not.

Disclaimer: The information on this page may have been obtained from third parties and does not necessarily reflect the views or opinions of KuCoin. This content is provided for general informational purposes only, without any representation or warranty of any kind, nor shall it be construed as financial or investment advice. KuCoin shall not be liable for any errors or omissions, or for any outcomes resulting from the use of this information. Investments in digital assets can be risky. Please carefully evaluate the risks of a product and your risk tolerance based on your own financial circumstances. For more information, please refer to our Terms of Use and Risk Disclosure.