Coldcard Hardware Wallet Exploit Exposes Infrastructure Vulnerabilities
A recent spate of crypto thefts has highlighted the vulnerabilities in infrastructure that can compromise even the most secure transactions.
In July 2026, roughly $247 million was stolen from crypto users, making it the second-worst month on record for theft this year.
The bulk of these losses were attributed to a hardware wallet exploit tied to Coldcard, a Canadian manufacturer of Bitcoin-only hardware wallets. According to TRM Labs, attackers drained approximately 1,816 BTC (worth about $116 million) from more than 5,200 addresses in four suspected waves that began on July 30.
The root cause of the issue wasn't a stolen device or leaked PIN, but rather a firmware integration error that caused affected units to rely on a predictable software random-number generator instead of the hardware-based source they were designed to use when creating wallet seeds. This flaw affected firmware versions 4.0.1 through 4.1.9 on Coldcard Mk2 and Mk3 devices, which had been vulnerable since March 2021.
This technical damage was severe, as seeds generated on vulnerable Mk2 and Mk3 devices carried only about 40 bits of effective entropy instead of the promised 128 bits.