Coinkite Coldcard flaw drains 1,778 Bitcoin in $112 million breach

Coinkite's Coldcard line has been hit by what is shaping up to be the largest hardware wallet breach on record after attackers drained more than 1,778 Bitcoin, worth roughly $112 million at prevailing prices, from over 5,000 addresses beginning on July 30, 2026. Galaxy Research linked the theft to a flaw in firmware version 4.0.1, released in March 2021, that generated a seed phrase (backup words that restore a wallet) with a pseudorandom number generator, or PRNG (software that simulates randomness), instead of the device's dedicated hardware random number generator, making wallet keys predictable. A developer had flagged a related issue to Coinkite as early as May 2025, Galaxy Research said, and at least a dozen distinct attackers later exploited the same weakness across Mk2, Mk3, Mk4, Q, and Mk5 devices. More than 1,000 BTC was swept from over 1,000 addresses within 41 minutes, and about 1,531 BTC remained untouched in attacker-controlled wallets as of mid-August 2026. Coinkite issued a security advisory on July 30 and patched affected models by July 31, but users who created wallets on vulnerable firmware must generate entirely new seed phrases and move funds immediately, a failure that also sharpens scrutiny of self-custody (holding your own crypto keys) as a security model.

The information on this website is generated using AI and we cannot guarantee its accuracy. Please use it as reference information only.