TechNewsReel
Live

Coldcard Mk3 Firmware Flaw Leads to $38 Million Bitcoin Theft

A critical vulnerability in Coinkite's hardware wallet allowed attackers to derive seed phrases and drain hundreds of air-gapped accounts.

TechNewsReel Newsroom · August 1, 2026

A critical vulnerability in the key generation process of Coldcard Mk3 hardware wallets has resulted in the theft of millions of dollars in Bitcoin. The flaw allowed attackers to derive private seed phrases and sweep funds from supposedly secure cold-storage devices without requiring physical access.

In a rapid 25-minute window between 01:31 and 01:56 UTC on July 31, 2026, attackers stole approximately 594 BTC, valued at roughly $38 million. The sweep targeted around 500 separate wallets, with the attackers specifically prioritizing accounts holding the largest balances to maximize the impact of the breach.

The Technical Failure

The vulnerability is tied to the firmware of the Coldcard Mk3, manufactured by Coinkite. Specifically, the flaw affects seeds generated on devices running firmware version 4.0.1 through 5.0.3. A Coinkite Security Advisory warned that seeds generated under these versions put user funds at risk, as the bug compromised the entropy or key generation process.

Cold wallets are widely regarded as the gold standard for cryptocurrency security because they keep private keys offline, creating an "air gap" between the funds and the internet. However, this incident demonstrates that the air gap is irrelevant if the software responsible for creating the keys is flawed. By exploiting the firmware bug, attackers were able to mathematically calculate the seeds, effectively bypassing the physical security of the hardware.

Industry Implications

This breach forces a significant re-evaluation of trust in hardware vendors and the perceived safety of cold storage. The fact that a systemic software error could expose hundreds of independent wallets simultaneously highlights a single point of failure in the key generation logic. For the broader industry, it serves as a reminder that hardware security is only as robust as the code driving it.

Users are now being urged to monitor their cold addresses more closely and migrate funds immediately upon the discovery of firmware vulnerabilities. The incident underscores the necessity of diversifying storage methods and the danger of relying on a single device manufacturer for massive holdings.

What Remains

While the immediate theft of 594 BTC has been documented, the full extent of the exposure for all users of firmware 4.0.1 and later remains a primary concern. Users are advised to verify their firmware versions and follow official Coinkite recovery and migration protocols to secure their remaining assets.

Sources

Get a notification when a big story breaks. A few a day at most — no spam.