BTC/USD $68,420 +2.8%
ETH/USD $3,540 +1.4%
SOL/USD $142.80 -0.6%
BNB/USD $605.20 +0.9%
XRP/USD $0.62 -1.2%
DOGE/USD $0.18 +5.4%
BTC/USD $68,420 +2.8%
ETH/USD $3,540 +1.4%
SOL/USD $142.80 -0.6%
BNB/USD $605.20 +0.9%
XRP/USD $0.62 -1.2%
DOGE/USD $0.18 +5.4%
Bitcoin

$40M in BTC Stolen due to Coldcard wallet vulnerability

A critical vulnerability in the key-generation firmware of Coldcard hardware wallets has resulted in the theft of roughly 594 $BTC, worth approximately $38 million, from around 500 wallets. T

AnonymousCryptoCompass newsroom
July 31, 2026
3 min read
NEWS
$40M in BTC Stolen due to Coldcard wallet vulnerability
CryptoCompass editorial visual for bitcoin coverage.

A critical vulnerability in the key-generation firmware of Coldcard hardware wallets has resulted in the theft of roughly 594 $BTC, worth approximately $38 million, from around 500 wallets. The exploit was executed in a coordinated sweep lasting just 25 minutes, raising serious questions about the security of one of the most widely trusted cold-storage devices in the Bitcoin ecosystem.

What Went Wrong

The vulnerability, introduced in Coldcard firmware 4.0.0 in March 2021, caused devices to skip their hardware randomness generator and fall back to predictable software-based key generation seeded by non-secret chip data. In practical terms, this meant wallet seeds were not drawn from a sufficiently random pool, making private key reconstruction feasible for an attacker with knowledge of the flaw.

Block's security researchers said affected Coldcard devices may have generated wallet seeds using a "predictable periodic down-counter," including the device's serial number and internal clock, instead of sufficient hardware-generated randomness.According to Coinkite, seeds generated on Mk4 and Mk5 devices before version 5.6.0 and on Q devices before version 1.5.0Q had about 72 bits of entropy rather than the expected 128 bits.

All affected wallets were single-signature wallets holding more than 0.15 Bitcoin, most of which had been inactive for extended periods, with their creation dates spanning from 2021 to 2026, aligning closely with the vulnerability timeline.

The Attack and Its Aftermath

Roughly 594.48 BTC, worth about $38.3 million, was swept from around 500 single-signature wallets between 01:31 and 01:56 UTC on July 30, 2026, with 562 BTC later consolidated into a single address. That consolidating address has not yet moved its funds, according to on-chain monitoring data.

Coinkite stated in a blog post that it still has an ongoing investigation into the matter but "out of an abundance of caution" noted there could be risks if the seed was created using the Coldcard Mk3 with firmware version 4.0.1 and above, with the problematic firmware traced back to March 2021.

The company described the issue on those models as less severe but "still serious," while noting that TAPSIGNER, OPENDIME, and SATSCARD, three other Coinkite wallet products, are not affected because they use different codebases.

Users are urged to move funds to a new wallet, especially if they did not use a BIP-39 passphrase.Firmware updates cannot fix old seeds; users must migrate funds now.

Sources:CoinDesk: Major Bitcoin wallet flaw drains 594 BTC in 25-minute sweepBitcoin Foundation: Coldcard Hardware Bitcoin Wallet Bug Puts Years of BTC Seeds at RiskCryptopolitan: Coldcard flaw sparks fears after $38M Bitcoin wallet drain