Coldcard Firmware Flaw Enables $70 Million Bitcoin Theft
A critical randomness failure in hardware wallets allowed attackers to mathematically reconstruct private keys without physical access.
A critical firmware vulnerability in Coldcard hardware wallets led to the theft of approximately 1,082.65 BTC, valued at roughly $70 million, on July 30, 2026. The exploit allowed attackers to computationally enumerate seed phrases, bypassing the physical security of the devices entirely.
Between 01:10 and 01:51 UTC, attackers drained 1,196 wallets in a rapid 41-minute window. The breach was caused by a firmware build setting that skipped the hardware randomness generator, forcing devices to fall back to a software substitute based on clock registers and the chip's serial number. For Mk4, Q, and Mk5 models, this caused the range of possible keys to collapse to approximately four billion—a number small enough to be enumerable by a standard computer. The attacker utilized a paid account at a well-known blockchain-services provider to query source addresses during the sweeps.
The Failure of Air-Gapping
Hardware wallets, known as cold storage, are designed to keep private keys offline to create an "air gap" between funds and the internet. The security of this system relies entirely on the entropy, or unpredictability, of the initial seed phrase. When the randomness used to generate that seed is flawed, physical isolation becomes irrelevant; the private key can be mathematically reconstructed by an external party on their own hardware.
Industry Implications
This attack undermines the core value proposition of cold storage by demonstrating that air-gapping is useless if the key generation process is deterministic. The incident highlights a systemic risk in the hardware ecosystem: users have no way to verify if their seeds were generated using vulnerable firmware. Consequently, a significant number of users may remain at risk without knowing their funds are exposed.
What's Next
While Coinkite, the maker of Coldcard, warned Mk3 owners and stated that newer devices are unaffected, reports suggest that Mk2, Mk4, Q, and Mk5 models may also be in scope. Users are encouraged to verify their firmware versions and monitor for further guidance on seed migration.