Friday, July 31, 2026
banner

An attacker swept 594 bitcoin from around 500 Coldcard wallets after a 2021 firmware change quietly replaced the device’s hardware randomness with a predictable software substitute.

Original Image Credits: Krakenimages.com / Shutterstock.com

Posted July 31, 2026 at 6:35 am EST.

An attacker swept roughly 594 bitcoin, worth about $38 million, out of around 500 separate wallets between 01:31 and 01:56 UTC on Thursday, in a theft traced to a flaw in how Coldcard, an air-gapped hardware wallet built by Toronto-based Coinkite, generated their key. About 562 BTC has been consolidated in a single address.

A wallet’s seed is supposed to be random and practically impossible to guess. But a build setting saw Coinkite’s devices build keys from a known unique identifier timer state and call history instead of a random number generator, according to a Thursday report from Block’s bitcoin engineering and security teams. The same fault also produced Coldcard’s paper wallet private keys, seed-splitting masks and device cloning keys.


This story is an excerpt from the Unchained Daily newsletter.

Subscribe here to get these updates in your email for free


Block said Exposure depends on the firmware a device was running when the wallet was created, not on when the hardware was bought, and a later upgrade does not repair a seed that was already generated. Anyone who exported an affected seed into a different wallet is still holding a weak one, the team warned.

The issue impacted Coldcard Mk3 models using v4.0.0, released in 2021, and later as well as models Mk4, Q and Mk5, according to Block. Coinkite in its advisory said “the impact on Mk4, Mk5 and Q is not as severe but is still serious.”

Coinkite told affected users that a BIP-39 passphrase leaves funds at minimal risk and recommended migrating to a seed generated on an unaffected device.

Every drained wallet was single-signature and held more than 0.15 BTC, and many had sat dormant for years, with the coins spanning 2021 to 2026, a range that tracks the bug’s age almost exactly.

The disclosure comes days after Zilliqa halted native transactions over a flaw in the Ledger signing app it created that let attackers rebuild private keys from data already public on-chain, another weakness that had gone unnoticed since 2019.

Related Listen: Why Authorities Can’t Freeze Crypto Fast Enough: DEX in the City

AI-assisted content: This article was produced with the assistance of AI tools and was reviewed, edited, and fact-checked by a member of the Unchained editorial team before publication.

Bitcoin,Bitcoin security,Coinkite,Coldcard,yahooBitcoin security,Coinkite,Coldcard,yahoo#Coldcard #Firmware #Flaw #Lets #Attacker #Drain #Bitcoin #Users1785501582

banner
crypto & nft lover

Johnathan DoeCoin

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Ut elit tellus, luctus nec ullamcorper mattis, pulvinar.

Follow Me

Top Selling Multipurpose WP Theme

Newsletter

banner
crypto & nft lover

Johnathan DoeCoin

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Ut elit tellus, luctus nec ullamcorper mattis, pulvinar.

@2022 u2013 All Right Reserved. Designed and Developed by PenciDesign