Skip to content
Back to Guavy Wire
Crypto

$130 Million Stolen in Coldcard Hardware Wallet Hack

Instruments
BTC
Share

Coinkite, the Canadian manufacturer of Coldcard hardware wallets, has been hit by a major bug that allowed hackers to steal over $130 million worth of Bitcoin. The bug, which was discovered in August 2026, affected older models of the wallet and compromised their security.

The issue arose when Coinkite migrated its cryptography from libsecp256k1 to MicroPython's software fallback, called Yasmarang, during a firmware update. This change rerouted seed generation away from Coldcard's hardware random number generator and onto the software algorithm, which is not as secure.

The bug effectively reduced the search space for generating private keys from 128 bits to around 40 bits on older models. This made it relatively easy for hackers to guess the keys and access the wallets, with some attacks reportedly completing in just 41 minutes.

More on Crypto

Disclaimer: Guavy is a data and market intelligence provider, not an investment advisor. The information, signals, and market analysis provided by the Guavy API and related services are for informational purposes only and are not intended as financial advice, investment recommendations, or an endorsement of any particular trading strategy. Trading in volatile markets, including cryptocurrency, carries significant risk and may not be suitable for all investors. Past performance is not indicative of future results. Users should consult with a qualified financial professional before making any investment decisions. Guavy makes no guarantee of trading profits or financial returns.

Real-time market sentiment intelligence for apps, funds & agents

Location

729 55 Ave SW
Calgary AB T2V 0G4
Canada

© 2026 Guavy Inc