Coldcard Flaw Drains $70M in Bitcoin in 41 Minutes

Cracked Coldcard hardware wallet leaking stolen bitcoin after a firmware exploit

On July 30, 2026, a software flaw in the Coldcard hardware wallet let attackers drain 1,082.65 bitcoin, close to $70M, in just 41 minutes. The attack never touched a single device. It rebuilt private keys remotely, from seeds that had been generated with far too little randomness. Coinkite, the maker, has acknowledged the bug and shipped fixed firmware, but a patch does not repair a seed that is already compromised.

Key Takeaways

  • 1,082.65 BTC (close to $70M) swept from 1,196 addresses in 41 minutes.
  • The flaw traces back to a March 2021 firmware change that weakened key generation.
  • Coinkite has patched it, but affected seeds have to be fully migrated to new ones.

A 2021 Firmware Build That Made Keys Guessable

The size of the theft grew through the night. Early reports counted 594 bitcoin taken, around $38M, from roughly 500 wallets. The consolidated tally that researchers landed on later climbed to 1,082.65 bitcoin, close to $70M, pulled from 1,196 addresses. All of it played out between 01:10 and 01:51 UTC, spread across six blocks.

The root cause was a single code change. A commit dated March 1, 2021 altered the call that generated the seed, bypassing the dedicated hardware randomness peripheral on the STM32 chip. Key generation fell back on a software substitute instead, seeded by the chip serial number and its clock registers. The seeds came out with far less entropy than the 128 bits expected for a twelve-word BIP-39 phrase.

In practice, the space of possible keys collapsed to roughly four billion combinations. That is brute-forceable offline, without ever handling the device. A patient attacker only had to reconstruct the keys one by one, then sweep the vulnerable addresses at a chosen moment. Coinkite walked through the mechanism in the security advisory it published the same day as the attack.

The scenario echoes warnings that have been piling up for months. Researchers had already flagged blind spots in hardware wallet firmware, as seen in ZachXBT’s earlier warnings about Ledger devices. What made this one different is that the flaw sat dormant for more than four years before it was exploited all at once.


Coldcard
Advertisement – investing involves risk.

Which Coldcards Are Exposed, and What Coinkite Wants Done

The maker first pointed to Coldcard Mk3 units whose seed was generated on firmware between versions 4.0.0 and 5.0.3. The advisory was then widened to the Mk2, and later to certain Mk4, Mk5 and Coldcard Q units. The list of genuinely affected devices kept moving during the investigation, which fed real confusion among holders.

Coinkite has released a fixed Mk3 firmware, version 4.2.0. On one point the message is blunt. Installing the update is not enough. A patch restores clean randomness going forward, but it does not repair an already weakened seed. Funds still sitting on an address derived from a vulnerable seed stay exposed until they are moved.

The required fix is heavy. Users have to generate an entirely new phrase on a patched device, then carefully migrate every balance to the fresh addresses. For a holder who thought cold storage was exactly how you stayed safe, the exercise stings. It also recalls the run of thefts that hit protocols this summer, including the $35M drained from DeFi in six hours.

Coinkite added one detail that lingers. The maker assumes an AI was likely used to comb through its old firmware versions and surface the flaw. If that holds, it opens an era where old code long considered safe becomes a target again, once it is reread by tools that can audit years of history in a matter of hours.


Also on Cryptonomic:


Self-Custody Takes the Hit, ETFs Watch On

Long-time bitcoiners called the episode the worst blow ever dealt to self-custody. The sector’s central argument, “not your keys, not your coins,” just got turned on its head. Here the holder did have their keys, but keys built with an invisible defect. Trust in the hardware, the very base of self-custody, absorbs the shock head-on.

Changpeng Zhao responded by urging holders to split their funds across several wallets rather than trust everything to a single device. The Binance founder tempered his own advice, conceding that spreading funds across wallets brings its own risks, starting with more complex key management. His line came down to one idea: nothing is 100% safe.

For the investor still on the fence, the affair revives a very concrete question, that of how to weigh cold storage against a hot wallet. Each option carries its own trade-offs, and none of them excuses skipping what actually runs under the hood of your hardware.

On the market side, the reaction stayed measured. Bitcoin traded around $63,011, down 1.32% at the time, with no sharp drop tied to the theft. Over a longer horizon, it is the debate between self-custody and regulated products that comes out reinforced. Every hardware failure hands another argument to spot ETFs, which shift custody onto institutional players and appeal to the profiles that never wanted to manage a seed.

Follow the story on Cryptonomic.

Comments

No comments yet. Why don’t you start the discussion?

    Leave a Reply

    Your email address will not be published. Required fields are marked *