Markets by Trading view

The Coldcard Hack: How a 2021 Firmware Flaw Drained Over $70 Million in Bitcoin

Facebook
Twitter
LinkedIn

A hardware wallet is supposed to be the one place a hacker can’t reach. That assumption broke on July 30, 2026, when an attacker emptied more than 1,000 Bitcoin from Coldcard wallets without ever touching a single device. The running total has already passed $70 million, drained from 1,196 wallets in a 41-minute span, and analysts say it is still rising.

A March 2021 firmware bug sat in plain sight for years

Coldcard, built by Canadian firm Coinkite, generates the seed phrase that controls your coins. A firmware update shipped in March 2021 broke the check meant to switch on the device’s hardware random number generator. The software quietly fell back to a predictable substitute seeded by the chip’s serial number and internal clock.

The result: Mk3 seeds carried roughly 40 bits of entropy instead of the 128 bits a Bitcoin seed should have. Mk4, Mk5, and Q devices landed around 72 bits, which is better, but Coinkite still called it serious.

How $70 million left wallets no one touched

Because the seeds were guessable, the attacker never needed the hardware. They generated candidate seeds on their own machine, derived the addresses each would produce, and checked those against the public blockchain. The victim’s Coldcard could have been switched off in a safe on another continent.

The sweep ran for about 41 minutes early on July 30. Galaxy Research first mapped 1,082.65 BTC across 1,196 addresses, then flagged a second wave that lifted the tally past $75 million. Oddly, none of it has moved, the coins sit unspent across a handful of attacker addresses.

Which Coldcard owners are exposed, and what Coinkite says to do

Every drained wallet was single-signature and created after the March 2021 firmware release, the strongest link between the thefts and the bug. Owners who added a BIP-39 passphrase or rolled at least 50 dice during setup are safe, since that fed in randomness the attacker can’t rebuild.

Coinkite pushed emergency firmware on July 31: 4.2.0 for Mk3, 5.6.0 for Mk4 and Mk5, and 1.5.0Q for Q. Updating the firmware does not change or repair an existing seed. Affected users have to generate a fresh seed on fixed firmware and move their funds over.

What the Coldcard hack means for Bitcoin self-custody

The timing stings. Blockaid reported that crypto losses topped $1 billion in the first half of 2026, most of it from compromised keys and operational slips rather than smart-contract exploits. Its CEO, Ido Ben-Natan, said Coldcard fits that pattern, with the exposure starting at the key-generation stage.

It reopens the debate that followed the $1.5 billion Bybit heist: holding your own keys removes exchange risk but hands you every other risk. Some analysts expect skittish holders to lean toward regulated custodians and spot Bitcoin ETFs, which saw heavy outflows as the news spread and BTC slipped about 3%. For anyone weighing the trade-offs, the self-custody options now offered by mainstream players carry a sharper warning label than they did a week ago.

Author: Ayanfe Fakunle

The editorial team at #DisruptionBanking has taken all precautions to ensure that no persons or organizations have been adversely affected or offered any sort of financial advice in this article. This article is most definitely not financial advice.

See Also:

Korbit Sells 15 BTC and 60 ETH as Korean Trading Volume Drops 89% | Disruption Banking

Is Coinbase Safe? | Disruption Banking

Leave a Reply

Your email address will not be published. Required fields are marked *


The reCAPTCHA verification period has expired. Please reload the page.

Related Posts

Write your email to verify subscription

Loading...

Sign up for our free newsletter and receive the latest banking and fintech stories, straight to your inbox - every week