Coldcard Exploit Drains $38M from Bitcoin Wallets
Bitcoin's recovery in July was met with an unprecedented security incident on the final night of the month. A firmware vulnerability in Coldcard hardware wallets allowed an attacker to drain approximately $38.3 million from around 500 wallets in a 25-minute sweep.
The exploit, which went undetected for five years, silently bypassed the devices' random number generator and used a non-cryptographic pseudorandom algorithm instead of the actual STM32 hardware chip. The attacker's ability to narrow the search space made it easier to crack the affected wallets.
Bitcoin had closed July up 7 percent, its best monthly finish since the current bear-recovery cycle began. However, this resilience was built on flushed leverage, with average daily liquidations remaining well below the year's typical range for most of July.