Firmware flaw exposes Coldcard Bitcoin wallets to $70M theft; the attack spreads to 4,500 addresses as losses near $89M
Galaxy ResearchCoinkite

Firmware flaw exposes Coldcard Bitcoin wallets to $70M theft; the attack spreads to 4,500 addresses as losses near $89M

A firmware flaw in Coldcard Bitcoin wallets has led to nearly $89 million in losses across 4,585 addresses, with attackers exploiting weak keys generated by the device. The latest wave of attacks has drained 1,367 bitcoin, with the thefts evolving to target smaller balances and using complex transaction patterns.

CoinDesk+1 source2 August 2026 · 03:05 UTC
CuriousCats Full Story

A firmware vulnerability in Coldcard Bitcoin wallets has resulted in significant financial losses, with nearly $89 million drained from 4,585 addresses through three waves of attacks. The flaw, originating from a March 2021 firmware release, allowed attackers to exploit weak keys generated by the device.4

The first wave of attacks on July 30 saw 1,196 addresses compromised in just 41 minutes, resulting in the theft of 1,082.65 BTC worth approximately $70.2 million at the time. Subsequent waves have targeted smaller balances, with the latest draining 208 BTC from 1,912 addresses between Friday and Saturday, averaging just over 0.1 BTC per victim.2

The vulnerability stems from a deterministic software pseudorandom number generator (PRNG) used in seed generation, which allowed attackers to reproduce keys offline. Coinkite, the manufacturer, has released emergency firmware updates, but existing seeds remain vulnerable. Galaxy Research has indicated that the sweeping attacks are likely the work of a single operator, although it remains unclear if all three waves are coordinated.

Coinkite advises users to replace their seeds and emphasizes that a strong, unique BIP-39 passphrase can mitigate risks. However, the ongoing thefts highlight the critical need for enhanced security measures in cryptocurrency wallets.

The disclosure follows earlier research by Coinspect, which identified a separate weak-PRNG flaw in older software wallets that resulted in over $5 million in losses across multiple cryptocurrencies since May.

Key Insight
“Galaxy Research counts 1,083 bitcoin drained from 1,196 addresses in the July 30 opening wave; the latest sweep sends each victim's coins to separate pay-to-witness-script-hash outputs, complicating onchain tracking. The firm says the chain cannot reveal whether one operator is behind all three sweeps.”
CuriousCats studied:
1
CoinDesk
“Galaxy Research flagged a third wave of sweeps tied to weak Coldcard-generated keys, with the attacker now targeting smaller balances and changing how funds are collected onchain.”
CoinDesk →
2
The Hacker NewsThe Hacker News
“An attacker drained 1,196 Bitcoin addresses in 41 minutes on July 30, taking 1,082.65 BTC worth about $70.2 million at the time.”
The Hacker News →
Ask CuriousCats
What is a Coldcard Bitcoin wallet?
Why is the firmware flaw significant?
How many addresses were affected by the theft?
Are similar attacks common in cryptocurrency?
How does this loss compare to previous thefts?
Get your CIA-level briefing,
in real time.
CuriousCats monitors the internet every minute for you and brings you the most personalized brief of videos, social media posts, news and more.
Download the App
If you liked this, you’ll love your CuriousCats brief.
News, videos, opinions and more — without the noise.
Get CuriousCats