$130 Million Stolen in Coldcard Hardware Wallet Hack
Coinkite, the Canadian manufacturer of Coldcard hardware wallets, has been hit by a major bug that allowed hackers to steal over $130 million worth of Bitcoin. The bug, which was discovered in August 2026, affected older models of the wallet and compromised their security.
The issue arose when Coinkite migrated its cryptography from libsecp256k1 to MicroPython's software fallback, called Yasmarang, during a firmware update. This change rerouted seed generation away from Coldcard's hardware random number generator and onto the software algorithm, which is not as secure.
The bug effectively reduced the search space for generating private keys from 128 bits to around 40 bits on older models. This made it relatively easy for hackers to guess the keys and access the wallets, with some attacks reportedly completing in just 41 minutes.