BitBulteni

BitBulteni

Technology

Coldcard Exploit Uncovers $90 Million Bitcoin Theft from Predictable Seeds

A long-standing firmware vulnerability in Coldcard Mk2 and Mk3 wallets, allowing predictable seed generation, has led to the theft of over $90 million in Bitcoin from thousands of users. This incident underscores critical lessons in hardware wallet security and the enduring risks of software flaws.

By BitBulteni August 3, 2026

The cryptocurrency world is once again grappling with a significant security breach, as a five-year-old firmware vulnerability in Coldcard Mk2 and Mk3 hardware wallets has reportedly led to the theft of over 1,367 Bitcoin, valued at approximately $90 million. This alarming discovery, identified by Galaxy Research, reveals a flaw where certain 2021 firmware releases generated seed phrases using predictable software-based randomness rather than the robust hardware-generated randomness users expect from a high-security device. The consequence? Attackers could potentially guess seed phrases, compromising funds across more than 4,500 addresses.

Coinkite, the manufacturer behind Coldcard, confirmed the coding error on July 30, 2026, and promptly released fixed firmware (version 4.2.0). While their swift response to patch the vulnerability is commendable, the grim reality remains: installing the update does not retroactively secure seeds already generated on the flawed software. This means that users who initialized their wallets with the vulnerable firmware are still at risk, even after updating. The ongoing nature of the attacks, with new waves sweeping substantial amounts of BTC, highlights the urgency of the situation.

This incident serves as a stark reminder of the foundational importance of true randomness in cryptographic security. Predictability, even in the minutest degree, can become an Achilles' heel, undermining the very trust placed in hardware wallets designed to be impenetrable. For affected users, the advice is unequivocal and urgent: move your funds immediately from any addresses potentially compromised by a seed generated on the flawed software. For the broader crypto community, it emphasizes the continuous need for vigilance, independent security audits, and a deep understanding of the underlying technology, even for devices considered the gold standard in self-custody. The Coldcard exploit is a sobering lesson that even the most reputable hardware can harbor dormant vulnerabilities with devastating financial consequences.

Tags ColdcardBitcoinHardware WalletSecurityVulnerability

More in Technology