TechNewsReel
Live

Coldcard Seed Flaw Triggers Millions in Bitcoin Thefts

A 2021 firmware bug allowed attackers to derive private keys and drain funds from air-gapped wallets.

TechNewsReel Newsroom · August 3, 2026

A critical vulnerability in a March 2021 firmware release for Coldcard hardware wallets has led to a series of massive theft waves, compromising the security of one of the industry's most trusted air-gapped devices. The flaw allows attackers to derive private keys from weak seeds, resulting in the rapid draining of user funds.

The vulnerability originated when a firmware update erroneously used a software pseudo-random number generator (PRNG) instead of the device's hardware RNG to create wallet seeds. This failure in randomness produced predictable seeds, which attackers have since exploited in multiple waves. The first major sweep occurred on July 31, 2026, when approximately 594 BTC—valued at roughly $38 million—was drained from about 500 wallets in just 25 minutes.

The Scale of the Exploit

Following the initial July attack, the exploit continued to propagate. Total losses from the first three waves of attacks were reported at approximately 1,367 BTC, with a market value estimated between $88 million and $89 million. The crisis intensified in early August 2026, when Alex Thorn, Head of Galaxy Research, identified a suspected fourth attack wave. While reports on the exact volume of this latest wave vary, some sources indicate approximately 448 Bitcoin were swept during this period.

A Crisis of Self-Custody

Coldcard is widely regarded as a gold standard for security due to its air-gapped design, which prevents the device from ever connecting to the internet. The discovery that a fundamental flaw in seed generation could bypass these physical protections has caused significant alarm within the self-custody community. It undermines the primary value proposition of the hardware: the belief that a seed generated offline is inherently secure.

This incident underscores the catastrophic risk associated with RNG failures. Because the vulnerability exists at the seed level, the compromise is permanent for any wallet created with the flawed firmware. Users cannot simply install a software patch to secure their current funds; the only remedy is to migrate assets to an entirely new seed generated with corrected firmware.

The Race to Migrate

As attackers continue to scan the blockchain for affected addresses, a desperate race has emerged between users and thieves. Alex Thorn noted that unconfirmed transactions may provide some Coldcard users with a narrow window of opportunity to save their remaining funds before they are swept.

Industry observers are now monitoring for further attack waves and assessing whether other hardware wallet manufacturers have similar legacy RNG issues. For affected users, the priority remains the immediate transfer of funds to new, secure addresses, as any wallet born from the March 2021 firmware remains a target.

Sources

Get a notification when a big story breaks. A few a day at most — no spam.