Coldcard Firmware Flaw Exposed as $88.6M Worth of Bitcoin Stolen
A recent analysis by Galaxy Research has uncovered a significant flaw in the firmware of Coldcard Mk3 devices, allowing hackers to drain approximately $88.6 million worth of Bitcoin from affected addresses.
The attacks occurred across three coordinated waves, with the largest single wave happening on July 30, 2026, and sweeping 1,082.65 BTC ($70.2M) in just 41 minutes.
The flaw, present in firmware versions 4.0.1 and later, introduced in March 2021, caused the device's random number generator to produce weak, predictable outputs, allowing attackers to enumerate possible seeds offline and match them to real addresses on the blockchain.
The stolen funds have largely stayed put, sitting in a small number of attacker-controlled addresses, with no significant movement detected since the thefts. Users holding funds on compromised Mk3 wallets are being urged to generate entirely new seeds on newer models rather than simply transferring balances within the same hardware generation.