CyberSecurityBoardThreat Intel · CVEs · Products
Critical CVEs

Coldcard Hardware Wallet Flaw Linked to $70 Million Bitcoin Theft in 41 Minutes

August 1, 2026

On July 30, 2026, an attacker drained 1,196 Bitcoin addresses in 41 minutes, stealing 1,082.65 BTC worth approximately $70.2 million. Galaxy Research traced the sweep to a firmware flaw in Coldcard, a Bitcoin-only hardware wallet made by Canadian firm Coinkite.

The vulnerability stems from a March 2021 firmware integration error that routed seed generation to a deterministic software pseudorandom number generator (PRNG) instead of the STM32 hardware random number generator (RNG). This flaw allows an attacker who can determine or constrain the device UID, timer state, and prior RNG-call history to reproduce candidate output streams offline, potentially deriving wallet seeds.

Coinkite shipped emergency firmware for all affected models on July 31, but installing it does not repair existing seeds. Owners with exposed seeds are advised to generate new ones on patched firmware and move their coins. Restoring old seeds to updated firmware carries the weakness forward.

Affected firmware versions include Mk2 and Mk3 (4.0.0 through 4.1.9, fixed in 4.2.0), Mk4 and Mk5 (before 5.6.0), Q (before 1.5.0Q), and Edge builds (before 6.6.0X for Mk4/Mk5, before 6.6.0QX for Q). Coinkite estimates effective entropy at roughly 40 bits on Mk3 and about 72 bits on Mk4, Mk5, and Q, against 128 bits for a 12-word BIP-39 seed.

Seeds generated with at least 50 fair, independent, private dice rolls are not at risk from this bug alone. A strong BIP-39 passphrase creates a separate wallet, but Coinkite still recommends replacing the seed. Multisig helps only if the quorum is not entirely built from affected devices. TAPSIGNER, OPENDIME, and SATSCARD use different codebases and are unaffected.

No attacker has been named. Galaxy Research noted the sweep pattern identifies the operator, not the theft, as it looks identical to a legitimate coin movement. The disclosure follows Coinspect’s Ill Bloom research in early July, a separate weak-PRNG flaw in older software wallets tied to over $5 million in thefts across multiple blockchains.

CVEs: CVE-2026-50522

Companies: Coinkite, Galaxy Research, Block, Coinspect

Products: Coldcard, TAPSIGNER, OPENDIME, SATSCARD