Coldcard Wallet Hack Exposes $70 Million Security Flaw
A $70 million cryptocurrency trading disruption has exposed a critical vulnerability in the Coldcard hardware wallet. On July 30, 2026, attackers drained more than 1,000 BTC from 1,196 wallets over a 41-minute window.
The attack exploited a firmware flaw dating to March 2021 that weakened the randomness used to generate recovery seeds on certain Coldcard models. The affected devices fell back to a basic software substitute seeded from the chip's serial number and clock registers, data an attacker could narrow down or measure on a device of their own.
The attacker made one critical mistake: using a paid account at a blockchain data provider to query the source addresses during the sweeps. Block, a security firm, traced this activity with what its researcher Clay Garrett called 'extraordinary specificity, down to the number, timing and sequence of requests.'
Coldcard maker Coinkite has acknowledged the bug, apologized, and released emergency firmware updates. The company advised users who generated seeds on affected versions, Mk2, Mk3, Mk4, Mk5, and Q models, to create entirely new seeds on patched devices and carefully migrate funds.