Bitcoin cold wallet hack exposes five-year-old firmware flaw, drains $114M from Coldcard devices

1 hour ago 3



The hardware wallet industry built its reputation on a simple promise: keep your Bitcoin offline and keep it safe. That promise took a serious hit on July 30, 2026, when attackers began exploiting a vulnerability in Coinkite’s Coldcard hardware wallets, ultimately draining what revised estimates place at 1,816 BTC, roughly $114 million, from more than 5,200 addresses. Some estimates suggest total losses could climb past $130 million as sweep activity continues. The vulnerability traces back to firmware version 4.0.1, released by Coinkite in March 2021. The flaw compromised the randomness used when generating wallet seeds, which are the master keys from which all private keys in a Bitcoin wallet are derived. Key strength, which ideally sits at 128 bits of entropy, dropped as low as 40 bits in affected devices. At 40 bits, brute-force attacks become computationally feasible with modern hardware. By early August, Galaxy Research estimated losses at approximately 1,367 BTC across 4,585 addresses. As attackers continued sweeping vulnerable wallets in subsequent waves, that figure climbed to 1,816 BTC implicated across more than 5,200 addresses. The progression matters because it signals...

Read Entire Article