Coldcard Hack Exposes Flaw in Hardware Wallet Security
A critical firmware vulnerability in Coldcard hardware wallets has led to an estimated $130 million loss of Bitcoin. Coinkite, the company behind Coldcard, is refusing to estimate the exact amount stolen, but independent researchers have identified around 2,055 BTC as compromised across over 7,300 addresses.
The attack began on July 30, 2026, and continued through August 3, with attackers exploiting a flaw in the random number generator used during seed phrase creation. This allowed them to reconstruct private keys offline, without needing an internet connection or any social engineering tactics.
Coinkite has acknowledged the issue and released a patch for firmware versions 4.0.1 through 4.1.9, urging users to generate new seed phrases and transfer their funds immediately. However, the company is not announcing any compensation fund or insurance mechanism for affected users.
The incident has raised concerns about regulatory standards for hardware wallet security, with no mandatory certification or audit framework currently in place. This lack of oversight has become increasingly apparent as 73 victims have reported losses to Galaxy Research and the total damage sits at $130 million.