OKX Banner
BTC $64,049.00 (+0.30%)
ETH $1,874.32 (+0.30%)
BNB $593.15 (+0.10%)
XRP $1.08 (-0.90%)
SOL $74.01 (+0.10%)
TRX $0.33 (+0.50%)
HYPE $55.72 (+1.70%)
DOGE $0.07 (-0.30%)
LEO $9.75 (+0.00%)
RAIN $0.01 (-2.10%)
ZEC $500.68 (+1.20%)
ADA $0.19 (-1.40%)
XMR $362.92 (-0.10%)
LINK $8.19 (-0.90%)
XLM $0.17 (-1.30%)
CC $0.11 (-2.90%)
BCH $213.93 (+0.50%)
GRAM $1.39 (-1.40%)
USDG $1.00 (-0.10%)
LTC $44.65 (+0.70%)

Coldcard Wallet Flaw Exploited as Hackers Steal $38M in Bitcoin from 500 Wallets

Twitter icon  •  Published 4日前 on July 31, 2026  •  Hassan Maishera

Hackers stole 594 BTC worth about $38 million after exploiting a Coldcard hardware wallet firmware flaw that generated predictable wallet seeds between 2021 and 2026.

Coldcard Wallet Flaw Exploited as Hackers Steal $38M in Bitcoin from 500 Wallets

TL;DR

  • Hackers stole approximately 594 BTC, worth about $38 million, from around 500 Coldcard wallets by exploiting a key generation flaw.

  • Researchers traced the vulnerability to Coldcard firmware released in March 2021, which generated predictable wallet seeds instead of using secure hardware randomness.

  • The stolen funds were consolidated into a single wallet after more than 1,300 transfers executed within minutes.

Hackers have stolen approximately 594 Bitcoin (BTC)—worth about $38 million—from roughly 500 Bitcoin wallets after exploiting a vulnerability in how Coldcard hardware wallets generated cryptographic keys.

According to a report published by Block's Bitcoin engineering and security teams, the coordinated attack took place between 01:31 and 01:56 UTC on Friday, draining funds from hundreds of wallets within minutes.

Attack Drained 500 Wallets in Minutes

Researchers said attackers transferred the stolen funds through 1,324 Bitcoin outputs across 500 transactions during a span of just three blocks on the Bitcoin blockchain.

Following the theft, approximately 562 BTC was consolidated into a single Bitcoin address, where the funds have remained unmoved.

The compromised wallets all shared similar characteristics:

  • They were single-signature wallets.

  • Each held more than 0.15 BTC.

  • Many had remained inactive for several years.

  • The affected wallets were created between 2021 and 2026, matching the period during which the vulnerable firmware was available.

Coldcard, developed by Canadian hardware wallet manufacturer Coinkite, stores Bitcoin private keys offline to protect them from internet-based attacks.

The vulnerability was tied not to the hardware model itself but to the firmware version installed when a wallet's recovery seed was originally generated.

Normally, wallet seeds are created using high-quality hardware-generated randomness, making them effectively impossible to predict.

However, Block's investigation found that a firmware configuration error prevented Coldcard from using its hardware random number generator.

Instead, the device generated wallet seeds using a basic software-based source of randomness derived from information such as the device's serial number and clock registers—values that are not secret and could potentially be reproduced or estimated by attackers.

Researchers traced the flaw to a firmware change introduced on March 1, 2021, which was first released in Coldcard firmware version 4.0.0 later that month.

Coinkite Identifies Potentially Affected Devices

Following the disclosure, Coinkite warned users who generated wallet seeds on Coldcard Mk3 devices running firmware version 4.0.1 or later to review their wallets.

The company said its preliminary investigation indicates that Mk4, Q, and Mk5 hardware wallets are not believed to be affected, although the investigation remains ongoing.

Block said it privately disclosed the vulnerability to Coinkite before publishing its findings. Both companies described their investigations as preliminary but said the report was released before full testing was complete because attackers were already actively exploiting the flaw.

Researchers warned that the flawed random number generator impacted more than standard wallet creation.

According to Block, the same vulnerable process was also used to generate: Paper wallet private keys, Seed-splitting masks, Device cloning keys, and Key Teleport transfer credentials.

Because these features also relied on predictable randomness, they may have been exposed to similar security risks.

 

Bitget’s Tokenized Stocks Surpass $1.16 Billion in Trading Volume
Next article Bitget’s Tokenized Stocks Surpass $1.16 Billion in Trading Volume
Hassan Maishera

Hassan is a Nigeria-based financial content creator that has invested in many different blockchain projects, including Bitcoin, Ether, Stellar Lumens, Cardano, VeChain and Solana. He currently works as a financial markets and cryptocurrency writer and has contributed to a large number of the leading FX, stock and cryptocurrency blogs in the world.