Skip to main content

Coldcard Firmware Flaw Enables Over $116 Million Bitcoin Theft in Largest Hardware Wallet Exploit

A five-year-old build error in Coinkite’s Coldcard hardware wallets reduced seed entropy, allowing attackers to drain 1,816 BTC worth $116M since late July.

By CryptoPress
August 6, 2026

  • Attackers exploited a March 2021 firmware bug in Coldcard wallets to drain approximately 1,816 BTC (~$116 million) across multiple waves starting July 30, 2026.
  • The vulnerability cut effective entropy to as low as 40 bits on older models, enabling remote brute-force of seeds without physical access.
  • Coinkite released emergency firmware fixes, but existing seeds remain vulnerable and require full migration to new wallets.
  • The incident ranks as the third-largest crypto hack of 2026, with most stolen funds still sitting in attacker addresses.

A five-year-old firmware configuration error in Coinkite’s Coldcard hardware wallets has enabled the largest hardware wallet exploit on record, with attackers draining roughly 1,816 BTC valued at approximately $116 million from more than 5,200 addresses since July 30, according to TRM Labs analysis.

The flaw originated in firmware version 4.0.1 shipped in March 2021. A build flag set the macro MICROPY_HW_ENABLE_RNG to zero, causing seed generation to fall back on a weak software pseudorandom number generator instead of the device’s dedicated hardware random number generator. This reduced effective entropy from the intended 128 bits to about 40 bits on Mk3 devices and roughly 72 bits on Mk4, Mk5 and Q models, as detailed in Coinkite’s technical backgrounder.

Attackers began sweeping vulnerable single-signature wallets on July 30, moving hundreds of BTC in the first wave alone within minutes. Subsequent waves followed, with Galaxy Research and TRM tracking cumulative losses that continue to climb. Most stolen bitcoin remains consolidated in a small number of attacker-controlled addresses with limited laundering observed so far.

In its security advisory, Coinkite confirmed the issue affects seeds generated on vulnerable firmware and stressed that firmware updates protect only newly created seeds. “Updating the firmware does not repair an existing seed,” the company stated. Affected users must generate an entirely new seed on patched firmware (version 4.2.0 or later for Mk3, 5.6.0 or later for Mk4/Mk5, and 1.5.0Q or later for Q) and migrate funds after testing with a small transaction.

Coinkite CEO Rodolfo Novak, known as @nvk, took full accountability in a public statement, saying the team was “heartbroken” and that the company had shipped emergency fixes while working around the clock to scope the damage. The company noted its open-source code was likely reviewed with AI assistance by the attackers.

The exploit has prompted broader questions about reliance on hardware wallets for self-custody. TRM Labs ranked the event as the third-largest crypto incident of 2026, contributing to more than $1.2 billion in total losses across 276 hacks this year. Bitcoin has also seen elevated exchange inflows in the days following the first wave as some holders moved coins to centralized platforms.

Users who added substantial dice entropy during setup or employed a strong unique BIP-39 passphrase face lower risk, but Coinkite still recommends migration for caution. TAPSIGNER, Opendime and Satscard products remain unaffected.

Related

© Cryptopress. All rights reserved.