← Back to Feed
Coldcard Hardware Wallet Flaw Linked to $70 Million Bitcoin Theft in 41 Minutes
August 1, 2026 · The Hacker News · Severity: MEDIUM
A firmware flaw in Coldcard hardware wallets allowed an attacker to drain 1,196 Bitcoin addresses in 41 minutes, stealing about $70.2 million. The flaw caused seed generation to use a deterministic pseudorandom number generator instead of the hardware random number generator. Coinkite released emergency firmware but warns that existing seeds are still vulnerable.
Key Takeaways
- A Coldcard firmware flaw enabled a $70 million Bitcoin theft in 41 minutes.
- The flaw routed seed generation to a deterministic PRNG instead of hardware RNG.
- Coinkite shipped emergency firmware but existing seeds remain compromised.