
A Coldcard firmware flaw let attackers steal $70M in Bitcoin by rebuilding private keys offline. See who is affected and stay safe.
Author: Akshat Thakur
2nd August 2026 – A Coldcard vulnerability has drained more than $70 million in Bitcoin. Attackers swept over 1,000 wallets without ever touching a single device.
High Signal Summary For A Quick Glance
Curry
@curry6912
@COLDCARDwallet thanks alot coldcard. Im on vaction and now changed my flight to get home today to get to my wallet. If my wallet is drained before i get home will you reimburse me since it was your weak security?
The first post was the advisory and what users should do. This second post has the technical details: what actually went wrong, why our reviews missed it, the impact across Mk3/Mk4/Q/Mk5, and what we changed. https://t.co/HshUxevCl3 ( current evaluating Mk3 firmware release ) https://t.co/Yfdx4XcztA
10:43 PM·Jul 31, 2026
MetatronicDave
@MetatronicDave
@COLDCARDwallet How could cold wallet holders get drained? Sounds like an inside job.
The first post was the advisory and what users should do. This second post has the technical details: what actually went wrong, why our reviews missed it, the impact across Mk3/Mk4/Q/Mk5, and what we changed. https://t.co/HshUxevCl3 ( current evaluating Mk3 firmware release ) https://t.co/Yfdx4XcztA
10:00 PM·Jul 31, 2026
immutable
@only21mm
@COLDCARDwallet @nvk any reports of MK4’s being drained? how quickly should MK4 users move or upgrade?
The first post was the advisory and what users should do. This second post has the technical details: what actually went wrong, why our reviews missed it, the impact across Mk3/Mk4/Q/Mk5, and what we changed. https://t.co/HshUxevCl3 ( current evaluating Mk3 firmware release ) https://t.co/Yfdx4XcztA
07:23 AM·Jul 31, 2026
Steady attention without excessive speculation.
The flaw sits in firmware for Coinkite’s Coldcard hardware wallets. It weakened random seed generation, so attackers could rebuild private keys offline and sweep the funds. Coldcard has long ranked among the most trusted Bitcoin self-custody devices.
A Coldcard normally builds its seed using a hardware true random number generator, or TRNG. That chip produces strong, unpredictable entropy.
Around March 2021, a firmware change broke that path. Because of a faulty code guard, seed generation quietly fell back to a weak software random generator from MicroPython.
As a result, entropy collapsed. On the Mk2 and Mk3, effective randomness dropped to roughly 40 bits instead of the intended 128.
That gap matters enormously. At 40 bits, a determined attacker can simply enumerate the possible seeds offline and match them to funded addresses.
Later models fared better, but not well enough. On the Mk4, Mk5, and Q, entropy reportedly fell to around 72 bits, according to Coinkite’s technical backgrounder.
The main attack unfolded fast. On July 30, 2026, attackers swept 1,196 addresses between roughly 01:10 and 01:51 UTC.
Galaxy Research mapped the flow. In total, the firm tracked 1,082.65 BTC drained in full, worth about $70.2 million at the time.
The transactions shared a clear signature. Each one used an identical 30 sat/vB fee, left no change output, and emptied the address completely.
That pattern helped researchers connect the theft. Engineers at Block first flagged it, and Galaxy then built on their work to trace the funds.
The sweeps also beat the public warning by roughly 30 hours. So many victims learned of the Coldcard vulnerability only after their Bitcoin was gone.
The stolen Bitcoin then pooled into a handful of wallets. One consolidation address, bc1qq85v2c9, held about 562 BTC in early reports, and the funds stayed largely unspent.
Losses have kept climbing since. By August 1 to 2, on-chain trackers counted about 1,367 BTC, near $88.6 million, across roughly 4,585 addresses.
Key milestones in the Coldcard Firmware Exploit
Coldcard firmware ~v4.0.0/4.0.1 is released with a seed-generation RNG fallback bug. No on-chain impact for over five years.
Attacker drains 1,196 addresses of 1,082.65 BTC (~$70.2M) across blocks ~960,183–960,191 using fixed 30 sat/vB fees and no-change outputs — ~30 hours before any public disclosure.
Coinkite/Coldcard warns that seeds generated on firmware 4.0.1+ may be at risk and urges careful migration for Mk3 users.
Coinkite expands advisory to Mk4/Mk5/Q firmware, releases emergency fixes (Mk3 4.2.0, Mk4/Mk5 5.6.0+, Q 1.5.0Q+), and accepts full accountability. Galaxy Research maps Wave 1; Wave 2 of ~76 BTC begins from additional addresses.
Third wave hits further addresses with a different pattern, often draining to individual P2WSH vaults. Galaxy Research updates totals progressively.
Galaxy Research’s running total stands at 1,367.05 BTC across three waves and 4,585 addresses. ~600 suspected attacker addresses reported to investigators; monitoring continues.
Coinkite did not dodge the blame. The company issued advisories, accepted responsibility for the firmware bug, and pushed emergency fixed firmware.
According to Coinkite, the flaw may have surfaced through AI-assisted review of its open-source code. “Both attackers and defenders have the same AI tools, but today it did not help us, and only helped the bad guys,” the company wrote.
Founder Rodolfo Novak, known as NVK, struck a somber tone. “Devastated, but my focus right now is on helping ppl rotate keys,” he wrote on X.
The attackers remain unidentified. Still, Block engineers noted they may have used a paid blockchain data provider account to find funded addresses.
Coinkite’s early scope also proved too narrow. At first the company treated later models as safe, then it widened the warning as evidence grew.
Here is the hard part. Updating firmware does not repair a seed that already carries weak entropy.
So a patched device can still hold a vulnerable key. To get safe, users must generate a fresh seed on fixed firmware and then move their funds across.
Coinkite has shipped those fixes. The patched versions include Mk3 4.2.0, Mk4 and Mk5 5.6.0, and Q 1.5.0Q.
Extra entropy also helps a lot. Seeds built with at least 50 private dice rolls, or protected by a strong BIP-39 passphrase, sit far out of reach.
The theft reopened an old argument. Critics quickly seized on it as proof that hardware wallets can fail.
Experts pushed back just as fast. They stressed that the attack never touched a device, and that fixed firmware plus a new seed restores security. As CoinDesk put it, the keys were rebuilt entirely offline.
Changpeng Zhao, the former Binance chief known as CZ, urged holders to split their funds. “Nothing is 100%,” he warned, according to Decrypt.
Others pointed to better habits. Multisig setups, external dice entropy, and unique passphrases would have shielded many affected wallets.
The Coldcard vulnerability is not fully contained. Because unmigrated seeds stay exposed, the exploit could keep draining wallets in the days ahead.
Affected users should act now. First, update to the fixed firmware. Then generate a brand new seed, and migrate funds with a small test transaction before moving everything.
Long-term single-sig holders face the highest risk. Anyone who set up a Coldcard seed on version 4.0.1 or later should treat their funds as exposed. This is especially true for seeds made without dice rolls or a passphrase.
None of this counts as financial advice. Still, when private keys are on the line, moving early beats waiting. You can follow migration steps in Coinkite’s official advisory.
Our Crypto Talk is committed to unbiased, transparent, and true reporting to the best of our knowledge. This news article aims to provide accurate information in a timely manner. However, we advise the readers to verify facts independently and consult a professional before making any decisions based on the content since our sources could be wrong too. Check our Terms and conditions for more info.
Coldcard Vulnerability Drains $70M From Bitcoin Wallets
Bybit Disavows “BILLI” Token and BybitBilli Account as Scam
Verus Ethereum Bridge Hack Drains $7.5M in Repeat Exploit
Zilliqa Confirms ZIL Hack From Exchange Partner’s Cold Wallet
Coldcard Vulnerability Drains $70M From Bitcoin Wallets
Bybit Disavows “BILLI” Token and BybitBilli Account as Scam
Verus Ethereum Bridge Hack Drains $7.5M in Repeat Exploit
Zilliqa Confirms ZIL Hack From Exchange Partner’s Cold Wallet