← Back to Feed

Coldcard Hardware Wallet Flaw Linked to $70 Million Bitcoin Theft in 41 Minutes

August 1, 2026 · The Hacker News · Severity: MEDIUM

A firmware flaw in Coldcard hardware wallets allowed an attacker to drain 1,196 Bitcoin addresses in 41 minutes, stealing about $70.2 million. The flaw caused seed generation to use a deterministic pseudorandom number generator instead of the hardware random number generator. Coinkite released emergency firmware but warns that existing seeds are still vulnerable.

Key Takeaways

  • A Coldcard firmware flaw enabled a $70 million Bitcoin theft in 41 minutes.
  • The flaw routed seed generation to a deterministic PRNG instead of hardware RNG.
  • Coinkite shipped emergency firmware but existing seeds remain compromised.
☕ Buy a Coffee