TechNewsReel
Live

Coldcard Firmware Bug Leads to $70.2 Million Bitcoin Theft

A critical flaw in the hardware wallet's key generation process allowed attackers to drain 1,082.65 BTC from 1,196 addresses.

TechNewsReel Newsroom · August 15, 2026

A critical firmware vulnerability in Coldcard hardware wallets has resulted in the theft of more than 1,000 Bitcoin, shaking confidence in the security of cold storage. The breach highlights a systemic failure in the device's cryptographic randomness, leaving users exposed to targeted attacks.

According to reports from Forbes and The Hacker News, attackers stole 1,082.65 BTC, valued at approximately $70.2 million, from 1,196 separate addresses. The theft was made possible by a bug in the firmware that caused the wallets to use predictable software-based key generation seeded by chip data. This flaw bypassed the secure randomness generator required to create truly unique and private keys, allowing attackers to mathematically derive and hijack user funds.

The Failure of Cold Storage

Coldcard, produced by the Canada-based company Coinkite, is marketed as a high-security, bitcoin-only wallet. Its primary value proposition is the use of air-gapped transaction signing, which ensures that private keys never touch an internet-connected device. By design, this architecture is intended to eliminate the risk of remote hacking. However, because the vulnerability existed at the point of key generation—the very foundation of the wallet's security—the air-gap provided no protection against the exploit.

Industry Implications

This incident undermines the perceived reliability of hardware wallets, which are widely regarded as the gold standard for long-term asset protection. When the fundamental process of seed generation is compromised, the entire security model of the device collapses. The breach has sparked urgent warnings across the industry; Samson Mow, CEO of Jan3, advised all Coldcard users, regardless of their firmware version or model, to migrate their funds to new seeds immediately to avoid potential loss.

Accountability and Recovery

Coinkite CEO Rodolfo Novak has taken full accountability for the firmware bug, acknowledging that the company's internal review process failed to identify the flaw before deployment. In response to the crisis, Coinkite has issued emergency firmware updates to patch the vulnerability. However, because the affected seeds were generated using a flawed process, a firmware update alone cannot secure existing funds. Users must generate entirely new seeds on patched devices and move their assets to those new addresses to ensure their Bitcoin is safe. The industry now faces a broader conversation regarding the auditing of cryptographic libraries and the risks of software-based randomness in hardware security modules.

Sources

Get a notification when a big story breaks. A few a day at most — no spam.