Coldcard Wallet Hackers Drain Over $112M Worth of BTC
The largest hardware wallet breach on record has left over $112 million worth of Bitcoin missing. The attack, which began on July 30, 2026, exploited a vulnerability in Coldcard firmware that allowed attackers to drain more than 1,778 BTC from over 5,000 addresses.
The bug was introduced in March 2021 with the release of firmware version 4.0.1 and went unpatched for five years. Instead of using the device's dedicated hardware random number generator, the flawed code rerouted the process to a software-based pseudorandom number generator, making it predictable.
A developer flagged the issue in May 2025, but Coinkite did not release a patch until July 30, when the attacks began. The company issued a security advisory and made patched firmware available for affected models by July 31. However, users must generate new seed phrases on patched firmware and move all funds to the new wallets immediately.