Coinkite's Coldcard Hardware Wallets Hacked for $89 Million
A vulnerability in Coinkite's Coldcard hardware wallets has led to an estimated $89 million in Bitcoin being stolen from thousands of wallets. The exploit, which occurred in July and August 2026, was made possible by a firmware flaw that affected versions 4.0.1 through 4.1.9 and earlier releases of the device.
The issue arose because the devices generated wallet seeds using a software random number generator instead of a hardware one, making it mathematically feasible to reconstruct keys offline without ever touching the physical device.
According to Galaxy Research, the attacker's tactics evolved with each wave of attacks, specifically to evade tracing while picking off smaller balances. The company noted that each wave was likely conducted by a single operator.