Coinkite's Coldcard Wallets Hit by Critical Security Flaw
A critical security vulnerability in Coinkite's Coldcard hardware wallets has led to the theft of approximately 1,367 Bitcoin, valued at $86 million as of August 3, 2026. The issue was caused by a flawed random-number generator used to create seed phrases, which are the master passwords for these wallets.
The vulnerability allowed attackers to predict security keys, bypassing the device's offline protection. Coinkite has released firmware updates to fix the problem and is advising users to apply them immediately. Over 4,500 user wallets were affected by this issue.
The total estimated loss rose significantly over the weekend as more affected wallets were identified. Some users reported losing their entire holdings in a matter of minutes after being exploited.