Coldcard Firmware Flaw Leads to $114 Million Bitcoin Drain
A critical entropy error in Coinkite's air-gapped wallets allowed attackers to guess seed phrases and sweep single-signature funds.
A critical firmware flaw in Coldcard hardware wallets has resulted in the theft of millions of dollars in Bitcoin, exposing a fundamental vulnerability in how the devices generated seed phrases. The exploit allowed attackers to predict private keys and drain funds from thousands of single-signature wallets.
The vulnerability stemmed from a firmware integration error introduced in March 2021. This flaw severely limited the entropy pool used to create seed phrases, making them guessable through brute-force attacks. The impact varied by device model: Mk3 devices saw entropy reduced to approximately 40 bits, while Mk4, Mk5, and Q models were reduced to approximately 72 bits. This weakness enabled a series of "sweep" attacks, where malicious actors identified and emptied vulnerable addresses.
The Scale of the Loss
Financial estimates of the damage evolved as the theft occurred in multiple waves. Initial reports cited losses of $38 million (594 BTC), with subsequent figures rising to $70.2 million across 1,196 addresses. The most recent estimates suggest total losses may approach $114 million.
Coldcard, produced by Coinkite, is marketed as a high-security, air-gapped, Bitcoin-only wallet designed to keep private keys entirely offline. However, the exploit proved that an air-gap is irrelevant if the underlying seed generation is flawed. The vulnerability specifically targeted single-signature wallets; multi-signature configurations, which require multiple independent keys to authorize a transaction, were not impacted.
Industry Implications
This incident serves as a significant warning for the hardware wallet industry, demonstrating that the use of certified secure elements does not guarantee security if the firmware implementation is defective. The event has reignited a critical debate within the cryptocurrency community regarding the risks of self-custody and the necessity for independent, public registry validation of entropy sources in security hardware.
Market Reaction and Next Steps
The discovery of the flaw triggered a massive spike in small Bitcoin transfers (under 1 BTC) on July 31, 2026, as panicked users rushed to move their remaining funds to safer addresses.
Users are now urged to verify if their devices were affected by the March 2021 firmware error. Those using single-signature wallets on the impacted models must migrate their funds to new wallets generated with corrected firmware or different hardware. The industry now faces pressure to implement more transparent auditing processes for the random number generators that form the bedrock of digital asset security.