TechNewsReel
Live

Coldcard Firmware Flaw Leads to $130 Million Bitcoin Theft

A critical failure in seed generation randomness allowed attackers to derive private keys for thousands of hardware wallets.

TechNewsReel Newsroom · August 14, 2026

A critical firmware vulnerability in Coinkite's Coldcard hardware wallets has resulted in the theft of approximately $130 million in Bitcoin. The flaw compromised the fundamental security of thousands of devices, allowing attackers to drain funds from an estimated 7,700 addresses.

The vulnerability stemmed from a failure in how the devices generated their recovery seeds. Instead of utilizing a true hardware random number generator (RNG), the firmware routed seed generation through a MicroPython software fallback. This pseudo-randomness drastically reduced the entropy of the generated keys, making them predictable and susceptible to brute-force attacks. According to reports, the stolen funds total between 1,596 and 2,055 BTC. Following the exploit, approximately 64 BTC and 200 ETH linked to the attack were moved into Wasabi Wallet and Tornado Cash mixers to obscure the trail.

The Failure of Cold Storage

Coldcard devices are marketed as high-security "cold storage" solutions, specifically designed to keep private keys entirely offline to prevent remote hacking. However, this exploit targeted the very foundation of that security: the randomness of the seed phrase. Because the keys were generated using a flawed process, they were predictable enough for attackers to derive them using data available on the public blockchain, rendering the "air-gapped" nature of the hardware irrelevant.

Industry Implications

This incident undermines the perceived absolute security of hardware wallets and highlights the catastrophic risk of pseudo-randomness in cryptographic implementations. When the source of randomness is compromised, the entire security model of a cryptocurrency wallet collapses, regardless of how secure the physical device is. The event serves as a stark reminder that software bugs in the most critical layers of a security product can lead to total loss of funds.

Current Status

Coinkite co-founder Rodolfo Novak has issued a public apology, stating that the company takes "full accountability for the firmware bug." Because the vulnerability is now public and the affected wallets are visible on the blockchain, the threat remains active. Users of affected firmware versions are urged to migrate their funds to new, secure wallets immediately to avoid further losses.

Sources

Get a notification when a big story breaks. A few a day at most — no spam.