1,367 BTC Stolen via Predictable Randomness Flaw in Coldcard Mk3 Firmware
A newly discovered firmware defect in Coldcard Mk3 devices has led to the theft of 1,367.05 BTC, worth approximately $88.6M, across three coordinated attack waves targeting 4,585 affected addresses.
The largest single wave hit on July 30, 2026, and it was efficient in the worst possible way. Attackers swept 1,082.65 BTC, roughly $70.2M, in just 41 minutes.
The flaw in Coldcard Mk3 firmware caused the device's random number generator to produce weak, predictable outputs, which allowed attackers with enough computing power to enumerate possible seeds offline and match them to real addresses on the blockchain.