BTC/USD $68,420 +2.8%
ETH/USD $3,540 +1.4%
SOL/USD $142.80 -0.6%
BNB/USD $605.20 +0.9%
XRP/USD $0.62 -1.2%
DOGE/USD $0.18 +5.4%
BTC/USD $68,420 +2.8%
ETH/USD $3,540 +1.4%
SOL/USD $142.80 -0.6%
BNB/USD $605.20 +0.9%
XRP/USD $0.62 -1.2%
DOGE/USD $0.18 +5.4%
Bitcoin

Coldcard Reports Differ on Whether $114M Was Stolen

crypto.news and CryptoBriefing both cover Coldcard's firmware fix but disagree on whether an actual theft of Bitcoin occurred. crypto.news and CryptoBriefing both cover Coldcard's firmware fi

AnonymousCryptoCompass newsroom
August 21, 2026
3 min read
NEWS
Coldcard Reports Differ on Whether $114M Was Stolen
CryptoCompass editorial visual for bitcoin coverage.

crypto.news and CryptoBriefing both cover Coldcard's firmware fix but disagree on whether an actual theft of Bitcoin occurred.

crypto.news and CryptoBriefing both cover Coldcard's firmware fix but disagree on whether an actual theft of Bitcoin occurred.

What all sources agree on

  • Coldcard released firmware versions 5.6.1 for Mk4 and Mk5 devices and 1.5.1Q for Q devices.
  • The update requires users to supply their own entropy (key presses, dice rolls, or coin flips) during seed generation.
  • The underlying flaw traces to a firmware change from March 2021 (version 4.0.1) affecting how seeds were generated.
  • Affected users are advised to create new wallets and migrate their Bitcoin rather than reuse old seeds.
  • The flaw reduced entropy on older Mk2/Mk3 units to roughly 40 bits, with lesser reductions on later models.
  • The firmware also addresses other areas including transaction signing and backup procedures.

Where the reports disagree

1Whether a theft of funds actually occurred

which addressed a flaw in how some versions of its firmware generated wallet seed phrases.

crypto.news 2026-08-20 19:05

attackers exploited a seed-generation vulnerability that drained approximately 1,816 BTC, worth roughly $114M to $116M, from affected wallets.

CryptoBriefing 2026-08-21 13:03

What would settle it: On-chain transaction records showing outflows from affected Coldcard wallet addresses, or a company statement confirming or denying stolen funds.

2Timeline and existence of an exploitation window before the hotfix

Coldcard said in an Aug. 20 post that the latest release followed three weeks of review after its July 31 emergency fix, which addressed a flaw in how some versions of its firmware generated wallet seed phrases.

crypto.news 2026-08-20 19:05

Attackers began exploiting the weakness on July 30, 2026. Coinkite responded the next day with an urgent hotfix on July 31, but the damage was already substantial.

CryptoBriefing 2026-08-21 13:03

What would settle it: A public incident report or security disclosure from Coinkite detailing whether active exploitation occurred between July 30 and July 31, 2026.

What to make of it

Treat the firmware versions, the entropy fix, and the migration advice as established; do not treat the $114M/1,816 BTC theft figure as confirmed until Coinkite or on-chain data verifies it.

Treat the firmware versions, the entropy fix, and the migration advice as established; do not treat the $114M/1,816 BTC theft figure as confirmed until Coinkite or on-chain data verifies it.

Originally reported by AltcoinGordon, written by Ethan Mercer. Republished with permission.

View the original on AltcoinGordon →

The post Coldcard Reports Differ on Whether $114M Was Stolen appeared first on TheCoinrise.com.