Coldcard Firmware Bug Lets Attackers Recreate Recovery Phrases, Drain 594 BTC
Image: Yellow

Coldcard Firmware Bug Lets Attackers Recreate Recovery Phrases, Drain 594 BTC

03 August, 2026.Crypto.20 sources

The story in 15 seconds

  • About 594 BTC (~$38 million) drained from roughly 500 Coldcard wallets in 15–25 minutes.
  • Seed generation used software RNG instead of hardware RNG, risking recovery phrases and private keys.
  • Stolen funds exceed $100 million across thousands of Coldcard wallets, Galaxy Research and Forbes.

The divide · 1 of 2

Coindesk ties hack to ETFs, while CBC emphasises AI and trust repair

Who skipped what

Blind spots

If you only read Other outlets, you would not know:

  • AI was believed used in the breach

Skipped by CryptoTicker, Tech Times

How each outlet frames it

Every outlet we compared, the headline it ran, and a link to the original article.

Source Diversity
20 sources
Western Alternative
8
Other
5
Western Mainstream
4
Local Western
1
Israeli
1
Asian
1

Western Alternative

@coindesk
@coindesk

Coldcard's $38 million (so far) exploit shakes faith in self-custody, may push investors to ETFs

31 July, 2026

Read the original →
AMBCrypto
AMBCrypto

All about Coldcard’s $38M Mk3 exploit and what’s next for Bitcoin self-custody

31 July, 2026

Read the original →
Bitcoin Magazine
Bitcoin Magazine

Coldcard Bug Exposes The New Reality: AI Is Auditing Every Open-Source Wallet

31 July, 2026

Read the original →
Bitcoin World
Bitcoin World

Coldcard Exploit Losses Top $70 Million As Key-generation Flaw Drains 1,000 BTC

01 August, 2026

Read the original →
Decrypt
Decrypt

Coldcard Bitcoin Exploit Explained: Entropy, How Keys Are Generated, and Why Bits Matter

04 August, 2026

Read the original →
FinanceFeeds
FinanceFeeds

The Bitcoin stolen in the Coldcard hardware wallet hack totals more than 1,367 BTC spread across 4,585 addresses.

03 August, 2026

Read the original →
TradingView
TradingView

Coldcard Security Notice Puts Bitcoin Wallet Entropy Risk Back In Focus

31 July, 2026

Read the original →
Yellow
Yellow

Fourth alleged wave of attack on Coldcard: 462 wallets affected, nearly 389 BTC siphoned

03 August, 2026

Read the original →

Western Mainstream

CBC
CBC

What we know about ongoing Coldcard hack that's stolen over $100M worth of bitcoin

04 August, 2026

Read the original →
Forbes
Forbes

Over $100 Million In Bitcoin Stolen By ‘Numerous’ Hackers—How A Software Bug Made It Possible

04 August, 2026

Read the original →
Fox Business
Fox Business

Coldcard wallet attack drains up to $89M in Bitcoin from 1,200+ addresses

02 August, 2026

Read the original →
TechCrunch
TechCrunch

Hackers steal over $130M by exploiting bug in offline hardware wallets

04 August, 2026

Read the original →

Local Western

Cointribune
Cointribune

Bitcoin: After $88 million vanished, Coinkite faces a sweeping class-action lawsuit.

03 August, 2026

Read the original →

Other

Computer Hoy
Computer Hoy

They had their Bitcoins stored in hardware wallets disconnected from the Internet, but they were robbed of 70 million dollars in 41 minutes: How is that possible?

04 August, 2026

Read the original →
CryptoTicker
CryptoTicker

594 BTC Gone in 25 Minutes: The Coldcard Flaw That Made Seed Phrases Guessable

31 July, 2026

Read the original →
Infosecurity Magazine
Infosecurity Magazine

Coldcard Users Lose $89m After Bitcoin Wallet Is Hacked

03 August, 2026

Read the original →
KuCoin
KuCoin

Coldcard Mk3 Seed Vulnerability Sparks Urgent Migration Amid 594 BTC Theft Probe

31 July, 2026

Read the original →
Tech Times
Tech Times

Coldcard Hardware Wallet Hacked via Firmware Bug That Bypassed RNG for Five Years

31 July, 2026

Read the original →

Israeli

The Jerusalem Post
The Jerusalem Post

Thousands of Bitcoin wallets hacked within half an hour

03 August, 2026

Read the original →

Asian

Vietnam.vn
Vietnam.vn

How did the shocking hack of offline Bitcoin wallets unfold?

03 August, 2026

Read the original →

Full story

Coldcard seed theft

A firmware bug in Coldcard hardware wallets let attackers recreate wallet recovery phrases and drain bitcoin from self-custody devices, with one report saying an attacker drained about 594 BTC worth over $38 million from 500 Coldcard wallets within about 15–25 minutes on July 30.

an attacker drained about 594 BTC worth over $38 million from 500 Coldcard wallets within about 15–25 minutes

AMBCryptoAMBCrypto

Coinkite CEO NVK told users in an open letter, "Move your funds now," after the flaw was patched but the fallout continued because updating firmware alone did not eliminate the risk for seeds already generated on vulnerable firmware.

Image from @coindesk
@coindesk@coindesk

A separate account said the sweep ended at 21:56 ET on Thursday night and that the attacker drained roughly 594 bitcoin from around 500 Bitcoin wallets, with 562 BTC ultimately consolidated into a single address that had not moved as of the time of writing.

AMBCrypto described the mechanism as a Coldcard Mk3 seed generation flaw that made some Mk3 recovery phrases predictable due to weak entropy, shrinking the number of guesses from 340 undecillion combinations to a few billion.

The same AMBCrypto report said that seeds generated on Mk4, Q, and Mk5 before the fixed firmware release were affected too, while other Coinkite hardware signers such as TAPSIGNER, OPENDIME, and SATSCARD remained unaffected.

AI, entropy, and debate

Security and industry voices framed the Coldcard incident as more than a single product failure, with Taproot developer Udi Wertheimer writing on X that "The idea of your bitcoin resting easy in some secret location while you enjoy life not worrying about it is currently unrealistic."

Blockaid co-founder and CEO Ido Ben-Natan said the incident highlights that "A hardware wallet's security ultimately comes down to the firmware and systems users interact with but never see," pointing to upstream safeguards before users take control.

Image from AMBCrypto
AMBCryptoAMBCrypto

Bitcoin Magazine said Coldcard MK3 devices with firmware version 4.0.1 through 4.1.9 were the worst affected, and it warned that 12- or 24-word seeds generated without user-generated dice rolls or a BIP 39 extra passphrase were vulnerable.

The same Bitcoin Magazine account quoted Coinkite’s updated July 31, 2026 advisory timing, including that "Mk4 and Mk5 users must update to version 5.6.0 or later" and that "For Mk3, update to version 4.2.0 or later."

In a separate explanation, Decrypt said Coinkite suspected the issue was found by machine and wrote, "We have to assume that someone used AI to review previous versions of our firmware and stumbled upon this issue," while also stating that fixed firmware does not repair existing seeds.

Migration, losses, and lawsuits

As losses and totals expanded across multiple waves, Galaxy Research was cited as tracking "1,596 BTC stolen from roughly 7,300 addresses" across three confirmed waves, with a suspected fourth wave that could lift the total to roughly 2,055 BTC.

"1,596 bitcoin stolen from roughly 7,300 addresses"

CBCCBC

CBC reported that Coinkite warned users to move funds after releasing firmware updates, and it quoted Coinkite’s Rodolfo Novak advising anyone who has generated a seed using a Coldcard wallet to "move your funds now."

Cointribune said Coinkite faces a sweeping class-action lawsuit after losses estimated at more than $88 million in Bitcoin, and it described Thomas Braziel as coordinating the collection of information from victims across several countries.

The same Cointribune account quoted Felipe Ojeda describing his experience as, "It was a 'spiritual guide' wallet, which only receives payments, and I kept it completely offline," before saying he filed a police report and planned to pursue legal action against Coinkite in his country.

Across the reporting, the practical consequence remained the same: Coinkite’s guidance required users to generate a new wallet and move funds onchain because updating firmware does not change or repair an existing seed, leaving affected holders to migrate even after patches.

The deep audit

How victims, perpetrators and terms are handled across outlets.

NewsCord Digest

Get every Crypto story like this one, in one email

Daily or weekly, only the topics you follow, each with the difference our analysis found across the outlets covering it.

Set up your digest

More on Crypto