Coldcard Hackers Drain $89 Million in Bitcoin from Thousands of Wallets
Hackers have exploited a firmware flaw in Coldcard hardware wallets, draining approximately 1,367 BTC valued at nearly $89 million from 4,585 addresses.
The vulnerability traces back to a March 2021 firmware build affecting Coldcard Mk3 versions 4.0.1 through 4.1.9 and earlier releases.
The flaw was in how those devices generated wallet seeds, using a software RNG instead of the hardware random number generator, making it mathematically feasible to reconstruct keys offline without ever touching the physical device.
The attackers' tactics evolved with each wave, specifically to evade tracing while picking off smaller balances. Coinkite released patched firmware by August 1, 2026, roughly two days after the first wave began.