Attackers Exploit Coldcard Firmware Flaw, Draining 1,082.65 BTC From 1,196 Wallets
Image: 디지털투데이

Attackers Exploit Coldcard Firmware Flaw, Draining 1,082.65 BTC From 1,196 Wallets

01 August, 2026.Crypto.18 sources

The story in 15 seconds

  • Attack drained 1,196 Coldcard wallets of 1,082.65 BTC in 41 minutes.
  • Losses estimated near $70 million.
  • Seed-generation flaw in March 2021 Coldcard firmware enabled remote key derivation without touching devices.

The divide · 1 of 2

24/7 Wall St. sensationalises with $70m without matching the technical scope others detail.

Who skipped what

Blind spots

If you only read Other outlets, you would not know:

  • Wave three used pay-to-witness-script-hash outputs.
  • Coinkite fixes cannot retroactively secure exposed seeds.

Skipped by CriptoTendencia, KuCoin, LCX Exchange

How each outlet frames it

Every outlet we compared, the headline it ran, and a link to the original article.

Source Diversity
18 sources
Other
8
Western Alternative
7
Local Western
1
Western Mainstream
1
Asian
1

Western Alternative

24/7 Wall St.
24/7 Wall St.

Coldcard Hacked for $70M: How Do You Keep Bitcoin Safe if Cold Wallets Can Be Hacked?

01 August, 2026

Read the original →
CoinDesk
CoinDesk

Bitcoin cold-wallet attack spreads to 4,500 addresses as losses near $89 million

01 August, 2026

Read the original →
Cointelegraph
Cointelegraph

Coldcard Bitcoin loss estimate rises to $70M after Galaxy analysis

01 August, 2026

Read the original →
Cryptonews.net
Cryptonews.net

Bitcoin losses linked to Coldcard vulnerability grow to $70 million, Galaxy Research says

01 August, 2026

Read the original →
CryptoRank
CryptoRank

Coldcard exploit losses top $70 million as key-generation flaw drains 1,000 BTC

31 July, 2026

Read the original →
DiarioBitcoin
DiarioBitcoin

Without touching the devices, the attack on Coldcard drained USD $70 million in BTC from 1,196 wallets.

01 August, 2026

Read the original →
Yellow
Yellow

Coldcard Loses $70M In 41 Minutes As CZ Warns Hardware Wallets Can Fail

01 August, 2026

Read the original →

Other

bitcoin.es
bitcoin.es

Bitcoin cold-wallet attack extends to 4,500 addresses with losses near $89 million.

01 August, 2026

Read the original →
CriptoTendencia
CriptoTendencia

Coldcard enfrenta un posible incidente de seguridad tras el vaciado de casi 1.200 billeteras de Bitcoin

01 August, 2026

Read the original →
Crypto Economy
Crypto Economy

Bitcoin losses from Coldcard vulnerability rise to $70 million, Galaxy Research warns.

31 July, 2026

Read the original →
Finanzen.net
Finanzen.net

Galaxy Maps Coldcard Bitcoin Losses After Wallet Incident

01 August, 2026

Read the original →
Koin Bülteni
Koin Bülteni

Critical Software Bug in Hardware Wallet Giant: $70 Million Worth of Bitcoin Stolen in Just 40 Minutes

31 July, 2026

Read the original →
KuCoin
KuCoin

Galaxy Research Expands Coldcard Wallet Incident to 1,082.65 BTC Loss

01 August, 2026

Read the original →
LCX Exchange
LCX Exchange

Coldcard Bitcoin loss estimate rises to $70M after Galaxy analysis

01 August, 2026

Read the original →
Pluang
Pluang

$70M stolen from Bitcoin Coldcard wallets due t...

31 July, 2026

Read the original →

Local Western

The Currency analytics
The Currency analytics

Galaxy Research estimates Coldcard Bitcoin loss at $70.2M across 1,196 wallets

01 August, 2026

Read the original →

Western Mainstream

The Hacker News
The Hacker News

Coldcard Hardware Wallet Flaw Linked to $70 Million Bitcoin Theft in 41 Minutes

01 August, 2026

Read the original →

Asian

디지털투데이
디지털투데이

Galaxy Research says 1,196 Coldcard addresses compromised, 1,082 bitcoin stolen

01 August, 2026

Read the original →

Full story

Coldcard seed flaw exploited

Galaxy Research said a Coldcard hardware wallet vulnerability tied to a March 2021 firmware release enabled attackers to drain bitcoin from thousands of wallets, with losses near $89 million and a third wave of sweeps spreading to 4,500 addresses.

losses near $89 million

CoinDeskCoinDesk

Reuters-aligned reporting in the same incident described an attacker draining 1,196 Bitcoin addresses in 41 minutes on July 30, taking 1,082.65 BTC worth about $70.2 million at the time.

Image from bitcoin.es
bitcoin.esbitcoin.es

The Hacker News said the March 2021 integration error routed seed generation to a deterministic software pseudorandom number generator instead of the STM32 hardware random number generator, letting an attacker reproduce candidate output streams offline.

Galaxy Research flagged that three distinct waves swept 1,367 bitcoin—nearly $89 million at recent prices—from 4,585 addresses, with the latest wave targeting smaller balances and using more complex, harder-to-trace transaction patterns.

The Hacker News added that Coinkite shipped emergency firmware for every affected model and release track on July 31, but installing it does not repair an existing seed.

Galaxy mapping and warnings

Galaxy Research said it identified 1,196 addresses involved in transactions tied to the July 30 sweep, tracing activity between 1:10 AM and 1:51 AM UTC across blocks 960,183 to 960,191.

The Hacker News reported that Block traced the fault to Coldcard's production config, defining MICROPY_HW_ENABLE_RNG as zero because Coinkite supplies its own hardware-RNG wrapper.

Image from CoinDesk
CoinDeskCoinDesk

Galaxy Research said the transactions share a recognizable on-chain pattern, including identical 30 satoshis per virtual byte fees and the absence of change outputs, while warning that later attacks may not reuse the same fingerprint.

Changpeng Zhao warned that “Even hardware wallets can have bugs,” and advised holders to split funds among several wallets.

Coinkite co-founder Rodolfo Novak said the company released a hotfix intended to remove the software fallback path, but warned that installing the fix does not retroactively protect seeds generated on vulnerable firmware.

What users must do next

Coinkite told users that if their seeds were created using vulnerable firmware, they must move their coins to a new seed, because “Restoring the old seed to updated firmware or another wallet carries the weakness forward.”

Restoring the old seed to updated firmware or another wallet carries the weakness forward.

The Hacker NewsThe Hacker News

The Hacker News said Coinkite estimates effective entropy at roughly 40 bits on the Mk3 and about 72 bits on the Mk4, Mk5 and Q, against 128 bits for a 12-word BIP-39 seed.

Galaxy Research cautioned that future attacks targeting Coldcard-generated addresses may not always follow the same on-chain “fingerprint,” meaning wallet owners should not assume the first identifiable traits will be reused.

The Hacker News said Coinkite stated a seed built with at least 50 fair, independent, private dice rolls is not at risk from this bug alone, while other affected users should migrate.

The Hacker News also noted that multisig helps only when the quorum is not built entirely from affected devices, and that TAPSIGNER, OPENDIME and SATSCARD use different codebases and are unaffected.

The deep audit

How victims, perpetrators and terms are handled across outlets.

More on Crypto