TechNewsReel
Live

Firmware Flaw in Coldcard Mk3 Wallets Leads to $116 Million Bitcoin Theft

A critical vulnerability in high-security hardware wallets allowed attackers to drain thousands of addresses by exploiting a deterministic seed generation path.

TechNewsReel Newsroom · August 4, 2026

A critical firmware vulnerability in Coinkite's Coldcard Mk3 hardware wallets led to a large-scale theft of Bitcoin in late July and early August 2026. The breach undermines the fundamental promise of cold storage by allowing attackers to compromise funds that were kept entirely offline.

The exploit targeted Coldcard Mk3 devices running firmware versions 4.0.1 through 4.1.9. According to reports from Fortune and other industry sources, the attack drained approximately 1,816 BTC—valued at roughly $116 million—across more than 5,200 addresses. The vulnerability specifically affected 12- or 24-word seeds that relied on the device's internal generation and did not utilize user-generated dice rolls or a BIP 39 extra passphrase.

The Technical Failure

Coldcard is marketed as a premier, Bitcoin-only hardware wallet designed for maximum security. However, the engineering team at Block identified the root cause of the breach as a deterministic MicroPython fallback path. This flaw effectively made the generated seeds guessable, significantly reducing the seed space and allowing attackers to recreate private keys without physical access to the devices. Block further reported that they were able to trace the attacker to a specific blockchain services provider.

Impact on the Market

The event occurred during a period of broader market volatility and geopolitical tension. While Bitcoin's price experienced a dip during this window, the breach served as a primary catalyst for investor anxiety. The theft is particularly devastating because it targeted users who had taken the highest possible precautions by using a dedicated cold storage device, shaking confidence in the perceived safety of hardware-based security.

The Future of Cold Storage

This breach highlights a systemic risk in relying solely on pseudo-random number generators (PRNGs) within hardware. It emphasizes the critical importance of manual entropy—such as using physical dice rolls—to ensure that seed generation is not dependent on potentially flawed software. Users of the Coldcard Mk3 are urged to verify their firmware versions and migrate funds if they used the affected versions without additional security layers. The industry now faces a reckoning over whether software-driven randomness can ever be truly trusted for high-value long-term storage.

Sources

Get a notification when a big story breaks. A few a day at most — no spam.