Skip to content
Back to Guavy Wire
Crypto

COLDCARD Hardware Wallets Hit in $38M BTC Heist Exploiting Five-Year-Old Firmware Bug

Instruments
BTC COL
Share

A significant breach of COLDCARD hardware wallets has been identified and disclosed. The attack drained approximately $38M worth of BTC from around 500 wallets in a 25-minute window between July 30, 01:31 and 01:56 UTC.

The root cause of the breach was a five-year-old firmware bug in COLDCARD's version 4.0.0, released in March 2021. The update deactivated the hardware random number generator on affected devices, replacing it with a predictable software fallback that used non-secret seed values.

The attacker exploited this flaw to replicate wallet seeds derived from device-specific metadata, targeting dormant accounts and pre-computing vulnerable seeds before scripting the draining process. Block's engineering team worked alongside Coinkite to identify the entity behind the attack and traced it to a blockchain services provider used during the theft.

More on Crypto

Disclaimer: Guavy is a data and market intelligence provider, not an investment advisor. The information, signals, and market analysis provided by the Guavy API and related services are for informational purposes only and are not intended as financial advice, investment recommendations, or an endorsement of any particular trading strategy. Trading in volatile markets, including cryptocurrency, carries significant risk and may not be suitable for all investors. Past performance is not indicative of future results. Users should consult with a qualified financial professional before making any investment decisions. Guavy makes no guarantee of trading profits or financial returns.

Real-time market sentiment intelligence for apps, funds & agents

Location

729 55 Ave SW
Calgary AB T2V 0G4
Canada

© 2026 Guavy Inc