Coldcard Hack Exposes Hardware Wallet Vulnerability
A firmware bug introduced by Coinkite in March 2021 compromised the security of Coldcard devices, making it mathematically feasible for attackers to reconstruct private keys without touching the physical device. The flaw redirected seed generation to a software-based pseudorandom number generator, rather than drawing from a robust source of entropy.
The first major attack wave occurred on July 30, 2026, with approximately $38 million in BTC disappearing from about 500 addresses in just 25 minutes. Galaxy Research identified at least three separate waves of attacks, resulting in total losses of between $114 and $116 million across over 5,200 compromised addresses.
The vulnerability affected the Coldcard Mk3 and other major models from the era, dating back to March 1, 2021. Coinkite's CEO and Block's engineering team confirmed the bug's existence, with emergency firmware updates issued to affected users. However, for many, this advice came too late.
The incident raises questions about the security of hardware wallets, which were previously considered the gold standard for offline storage. The timing is particularly significant, as it involves one of the most respected names in Bitcoin security culture. This may accelerate the move towards spot Bitcoin ETFs, which can provide institutional and retail investors with Bitcoin exposure without the need for wallet management.