VERSE PRESS

Crypto News, Global First.

Coldcard Firmware Bug Active Since 2021 Has Drained $89 Million in Bitcoin Across Three Attack Waves

An unidentified attacker has stolen 1,367 BTC, worth approximately $89 million, from nearly 4,600 Bitcoin addresses tied to Coldcard hardware wallets. The theft began July 30, 2026 and is described by manufacturer Coinkite as ongoing. The root cause is a firmware error introduced in March 2021 that silently disabled the device's hardware random number generator for over five years.

|

The first wave of the attack began at roughly 01:10 UTC on July 30. In roughly 25 to 30 minutes, the attacker swept approximately 594 BTC (around $38 million) from about 500 dormant single-signature wallets, moving funds across just six blockchain blocks.

Galaxy Research subsequently identified a second wave on August 1 and a third on August 2. The second wave alone drained 1,082.65 BTC from 1,196 addresses in approximately 41 minutes. Together, the three waves pushed total losses to roughly $89 million across 4,585 drained addresses. Galaxy has tracked approximately 600 addresses it suspects are under attacker control and has shared its findings with investigators and compliance firms. The jurisdiction of those investigators has not been publicly disclosed; Coinkite is incorporated in Canada.

What makes the attack unusual is that the attacker never physically touched a single device. The vulnerability stems from a faulty conditional check in a supporting firmware library, introduced during a March 2021 update. The check tested whether a configuration flag existed rather than verifying it was actually enabled. As a result, Coldcard devices skipped their dedicated STM32 hardware random number generator and fell back to a software-based substitute seeded with the device's chip serial number and internal clock registers. Both of those values are either publicly accessible or computationally reconstructible, meaning anyone with sufficient computing resources could derive the same seed phrases the devices generated. On Mk3 models, this collapsed effective seed entropy from the expected 128 bits down to roughly 40 bits. On Mk4, Q, and Mk5 models, the figure was approximately 72 bits, which still reduces the key search space to around 4 billion candidates. As CoinDesk reported, researchers described that figure as "a small number to a computer."

The attacker pre-computed candidate seed phrases offline, derived the corresponding Bitcoin addresses, cross-referenced them against the public blockchain ledger, and executed sweeps remotely. Block's Bitcoin engineering and security team found that the attacker used a paid account at a well-known blockchain data provider. Internal query logs at that provider matched, in the team's words, "with extraordinary specificity" the timing, sequence, and number of requests during each sweep wave.

Coinkite CEO Rodolfo Novak acknowledged in comments reported by Bitcoin Magazine that AI-assisted code review is suspected to have played a role in discovering or exploiting the latent bug. "AI-assisted code review can now find latent bugs at a speed outpacing even the industry's most seasoned experts," Novak said. The AI attribution is Novak's own characterisation of a possible explanation and has not been independently confirmed by outside investigators.


Coinkite published an emergency security advisory on July 30 and released patched firmware on August 1, roughly 48 hours after the first wave. All Coldcard firmware versions released between March 2021 and late July 2026 are affected, spanning the Mk2, Mk3, Mk4, Q, and Mk5 product lines. Specifically, affected versions include Mk2 and Mk3 devices running firmware 4.0.0 through 4.1.9; Mk4 and Mk5 devices running standard firmware before version 5.6.0; and Q devices running standard firmware before version 1.5.0Q. Full update instructions and version details are available at blog.coinkite.com/coldcard-mk3-seed-generation-warning/. The TAPSIGNER, OPENDIME, and SATSCARD product lines are not affected. Coinkite has stated clearly that adding a BIP-39 passphrase (an optional extra password layer) offers only partial interim protection and does not repair a compromised seed. The company recommends migrating funds to a freshly generated seed on patched firmware immediately. Seeds generated using at least 50 independent, private dice rolls as supplemental entropy are also not at risk.


The stakes are especially high for users in South Asia and Africa. India ranks first globally in the Chainalysis 2025 Crypto Adoption Index, and self-custody use has grown sharply since the 2024 WazirX exchange hack; analysts have noted that the incident prompted many holders to move funds off custodial platforms. Pakistan sits in the top five of the same index, driven by remittance use and inflation hedging, though Coldcard is less common there than Ledger or Trezor alternatives, with adoption concentrated primarily in urban tech communities in Karachi and Lahore. In South Africa, retailer Easy Crypto explicitly markets Coldcard as the country's most secure air-gapped hardware wallet option. In Nigeria, Bitcoin-only maximalists in Lagos and Abuja tech communities have a well-documented self-custody culture shaped partly by Central Bank restrictions on crypto-linked bank accounts; this characterisation draws on a source with a commercial interest in the hardware wallet market and has not been independently corroborated. Users in all of these markets frequently acquire Coldcard devices through informal channels, such as international resellers or personal networks, which means many may not have registered with Coinkite or received official security alerts. Local-currency exchange rates in INR and PKR amplify the real-world cost of even modest BTC losses, and there are no regional regulatory frameworks that would mandate disclosure or user remediation.


Coinkite's advisory directs affected users to blog.coinkite.com/coldcard-mk3-seed-generation-warning/ for firmware update instructions.

The incident stands apart from prior hardware wallet security failures because no physical access was required at any stage of the attack.

CoinDesk has noted that the episode may accelerate interest in Bitcoin ETFs among retail holders who now have doubts about self-custody, though that option remains inaccessible to most users in the markets most exposed to this attack.

Losses continue to accumulate as the attack remains ongoing.