Skip to content
Back to Guavy Wire
Crypto

Coldcard Hack Exposes Weakness in Hardware Wallets: $114M Stolen

Instruments
BTC
Share

A severe security failure has been unfolding at Coldcard, a device designed to make cryptocurrency storage secure. At least four sweeps have occurred, draining a total of nearly $114 million from affected wallets. Despite this, Bitcoin's price has not collapsed as many traders had expected.

The issue lies in the firmware used by Coldcard, which contained a software fallback for generating randomness. This allowed an attacker to reproduce candidate output streams offline, making it possible to guess seeds that were previously thought secure.

Coldcard's Mk3 firmware versions 4.0.1 through 4.1.9 are affected, as well as some Mk4, Mk5, and Q devices. Updating the device does not repair the issue, and users should generate a new seed and update their wallet before moving funds.

Coinkite, the company behind Coldcard, believes that AI tooling was used to find the bug, which sat undetected for over five years. The incident highlights the importance of verifying seeds at creation, rather than relying on after-the-fact checks.

More on Crypto

Disclaimer: Guavy is a data and market intelligence provider, not an investment advisor. The information, signals, and market analysis provided by the Guavy API and related services are for informational purposes only and are not intended as financial advice, investment recommendations, or an endorsement of any particular trading strategy. Trading in volatile markets, including cryptocurrency, carries significant risk and may not be suitable for all investors. Past performance is not indicative of future results. Users should consult with a qualified financial professional before making any investment decisions. Guavy makes no guarantee of trading profits or financial returns.

Real-time market sentiment intelligence for apps, funds & agents

Location

729 55 Ave SW
Calgary AB T2V 0G4
Canada

© 2026 Guavy Inc