TechNewsReel
Live

Coldcard Firmware Flaw Leads to $116 Million Bitcoin Theft

A critical failure in random number generation allowed attackers to drain thousands of air-gapped wallets.

TechNewsReel Newsroom · August 5, 2026

A systemic firmware vulnerability in Coldcard hardware wallets has resulted in the theft of an estimated $100 million to $130 million in Bitcoin. The exploit targeted users who utilized a specific 2021 update, allowing attackers to reconstruct seed phrases and drain funds from thousands of addresses without requiring internet connectivity, phishing, or physical access to the devices.

The theft occurred in waves around late July 2026. According to Galaxy Research, roughly 7,300 addresses were affected, with the amount of stolen Bitcoin estimated at 1,596 BTC, though some reports suggest the total could reach 2,055 BTC. The vulnerability originated in firmware version 4.0.0, released in March 2021. A build setting in that version caused the device to skip its hardware randomness chip, falling back instead to a predictable software substitute based on clock registers and serial numbers. This deterministic pseudo-random generator made it possible for attackers to guess the private keys of affected users.

The Failure of Air-Gapping

Coldcard wallets, produced by Coinkite, are marketed as "cold storage" solutions designed to remain entirely offline to ensure maximum security. This incident is particularly devastating because it bypassed the primary defense of air-gapping. Victims reported following every security best practice, including self-custody and keeping devices offline. Jonathan Goodman, a Canadian entrepreneur, described the psychological toll of the loss, stating he never shared his seed phrase and his devices never touched the internet, yet his funds were still emptied between July 29 and July 30.

The AI Threat Landscape

The breach highlights a shifting threat landscape where artificial intelligence is being used to identify latent software bugs. Rodolfo Novak, CEO of Coinkite, attributed the discovery of the flaw to the "new AI paradigm," noting that AI-assisted code review can now find vulnerabilities at a speed that outpaces even the most seasoned human experts. This suggests that open-source firmware, while transparent, may now be more susceptible to rapid analysis by adversarial AI tools.

Implications for Self-Custody

This event reignites the debate between individual self-custody and the use of regulated institutional custodians. For years, the industry has championed the "not your keys, not your coins" mantra, but this hack proves that "doing everything right" can still leave users exposed to systemic software failures. As users realize that hardware-level flaws can render air-gapping irrelevant, the industry may see a shift toward diversified storage strategies to mitigate the risk of a single point of failure in firmware.

Sources

Get a notification when a big story breaks. A few a day at most — no spam.