Coldcard Hackers Drain Over $85M in 5-Year-Old Bug
A security flaw in Coldcard's firmware allowed hackers to drain over $72 million from over 2,600 addresses. The bug, which has been present since March 2021, used a pseudo random number generator instead of a true one, making it possible for attackers to guess seed phrases and steal associated Bitcoin funds.
The first transactions were detected on July 30, 2026, and by Sunday, the tally had risen to over $85 million. Security researchers warned that additional waves of attacks could occur as hackers continued to crack private keys.
Coldcard's manufacturer, Coinkite, initially claimed that only Mk3 devices were affected but later admitted that Mk4, Mk5, and Q models also used the flawed firmware. The company released a patch, but it cannot repair compromised seed phrases.