Coldcard Firmware Flaw Leads to $70 Million Bitcoin Theft
A critical entropy vulnerability allowed attackers to computationally reconstruct seed phrases and drain funds from air-gapped wallets.
A critical firmware vulnerability in Coldcard hardware wallets has resulted in the theft of approximately $70 million in Bitcoin, proving that air-gapped security is irrelevant if the underlying seed generation is flawed. The exploit allowed attackers to computationally enumerate seed phrases, bypassing the need for physical access to the devices.
Between 01:10 and 01:51 UTC on July 30, 2026, attackers drained 1,082.65 BTC from 1,196 different addresses in a rapid 41-minute window. The vulnerability stemmed from a firmware build setting that caused certain models—specifically the Mk4, Q, and Mk5—to skip the hardware randomness generator. Instead, the devices fell back to a predictable software substitute based on clock registers and serial numbers. This failure collapsed the range of possible keys from an unimaginably vast number to roughly four billion possibilities, making them susceptible to brute-force attacks. Galaxy Research has since identified that the stolen funds are currently held in four addresses and have not yet moved.
The Failure of Air-Gapping
Coldcard, produced by Coinkite, is marketed as a high-security, Bitcoin-only wallet designed to keep private keys entirely offline. The core value proposition of such hardware is that because keys never touch the internet, they are theoretically immune to remote exploits. However, this incident demonstrates a systemic risk: the security of a hardware wallet is entirely dependent on the randomness of its seed generation. When that entropy is compromised, the physical isolation of the device provides no protection, as the keys can be reconstructed externally by an attacker with sufficient computing power.
Industry Implications
This breach undermines the fundamental trust in hardware-based self-custody. The incident is particularly damaging because users cannot easily verify whether their specific seed was generated using the secure hardware generator or the flawed software fallback. Consequently, a significant number of users may be at risk without any indication that their funds are vulnerable. This highlights a critical vulnerability in the self-custody model, where a single software bug in the manufacturing or firmware process can render expensive hardware security meaningless.
What's Next
Investigators are currently tracing the attacker's movements, noting that the perpetrator used a paid account at a blockchain data provider to query source addresses. While the stolen funds remain stationary in four addresses, the industry is now grappling with the broader implications of entropy failure. Users of affected Coldcard models are urged to verify their firmware versions and consider the security of seeds generated during the flawed build period.