TechNewsReel
Live

Coldcard Firmware Flaw Leads to $70 Million Bitcoin Theft

A critical vulnerability in air-gapped hardware wallets allowed attackers to drain over 1,000 BTC from nearly 1,200 addresses.

TechNewsReel Newsroom · August 1, 2026

A critical vulnerability in the key generation process of Coldcard hardware wallets has resulted in the theft of approximately $70.2 million in Bitcoin. The flaw allowed attackers to derive private keys remotely, undermining the security of devices designed as the gold standard for offline storage.

Analysis by Galaxy Research shows the exploit targeted 1,196 addresses, which were emptied of a total of 1,082.65 BTC. The crisis began with a rapid-fire attack on July 30-31, 2026, where 594 BTC—valued at roughly $38 million—was drained from approximately 500 wallets in a concentrated 25-minute sweep between 01:31 and 01:56 UTC. Reports from CoinDesk and The Block confirm that losses continued to climb as the scope of the vulnerability became clear.

The Firmware Failure

Coldcard is widely regarded as one of the most secure "air-gapped" hardware wallets available, meaning it is designed to never connect directly to a computer. However, the security of any wallet relies entirely on the randomness of its private keys. In this instance, a flaw in firmware 4.0.0 for the Mk3 model caused the device to skip the hardware randomness generator. Instead, the wallet relied on predictable software-based generation, making the resulting keys discoverable to attackers without requiring physical access to the hardware.

Industry Implications

This incident highlights a systemic risk inherent in hardware wallet firmware. Because the vulnerability existed at the foundational level of key generation, affected users cannot resolve the issue by simply updating a password or changing a setting. To secure their assets, users must migrate all funds to entirely new wallets generated with secure firmware. The speed and scale of the attack demonstrate how a single cryptographic error can be weaponized across a global user base in minutes, erasing the perceived safety of air-gapped systems.

What to Watch

Industry observers are now monitoring for further address drains as more users identify if their devices were affected by the flawed firmware. While the primary attack window has passed, the total number of compromised addresses may shift as Galaxy Research and other forensic firms continue to analyze the blockchain for related patterns of theft.

Sources

Get a notification when a big story breaks. A few a day at most — no spam.