Skip to content
Back to Guavy Wire
Crypto

COLDCARD Hardware Wallet Exploit Traced to Blockchain Services Provider

Instruments
BTC COL
Share

A $38 million Bitcoin theft has been linked to a blockchain services provider after Block's engineering team identified the entity behind the COLDCARD hardware wallet exploit. The breach, which occurred on July 30, drained approximately 594 BTC from around 500 wallets in a 25-minute window between 01:31 and 01:56 UTC.

The root cause of the vulnerability was a five-year-old firmware bug that made it possible for attackers to replicate wallet seeds derived from device-specific metadata. This flaw was introduced by a March 2021 firmware update, specifically version 4.0.0, which deactivated the hardware random number generator on affected COLDCARD devices.

The attacker appears to have sat on this knowledge for years, targeting dormant accounts before executing the draining process over a 25-minute window. Block and Coinkite coordinated an urgent disclosure of the vulnerability, allowing users to take immediate action to protect their funds.

More on Crypto

Disclaimer: Guavy is a data and market intelligence provider, not an investment advisor. The information, signals, and market analysis provided by the Guavy API and related services are for informational purposes only and are not intended as financial advice, investment recommendations, or an endorsement of any particular trading strategy. Trading in volatile markets, including cryptocurrency, carries significant risk and may not be suitable for all investors. Past performance is not indicative of future results. Users should consult with a qualified financial professional before making any investment decisions. Guavy makes no guarantee of trading profits or financial returns.

Real-time market sentiment intelligence for apps, funds & agents

Location

729 55 Ave SW
Calgary AB T2V 0G4
Canada

© 2026 Guavy Inc