Coldcard Firmware Bug Goes Unnoticed for Years, Enabling ~$100M Bitcoin Theft
A long-dormant bug in Coldcard's firmware, present since version 4.0.1 released in March 2021, led to the theft of roughly $100 million in Bitcoin on July 30, 2026. Galaxy Research tied the sweep to weak randomness in seed generation, and independent analysts later put losses as high as $116 million. Coldcard is one of the most trusted Bitcoin-only hardware wallets, yet a years-long flaw in its key-generation path validates the industry's 'don't trust, verify' maxim—as Foundation CEO Zach Herbert put it, reputation is not a security model. The incident may push users to demand stronger verification of hardware wallets and to reassess self-custody risks. The bug affected only some devices, causing generated seed phrases to have far weaker entropy than intended, and the coins swept by the attacker spanned 2021 to 2026. On July 30, about 1,196 addresses were drained in 41 minutes, taking 1,082.65 BTC; Coinkite's CEO initially denied a wallet-wide vulnerability, and attacks were reported to still be ongoing.
rss · CoinDesk · · Single source
Background, discussion, and references
Market impact
The theft is concentrated in Bitcoin and self-custody hardware wallets, so the transmission channel is user trust and perceived custody risk rather than exchange liquidity. If confidence in Coldcard erodes, some holders may shift to competing wallets, multisig setups, or custodial services, but the net effect on Bitcoin's price is not predetermined.
Background
A hardware wallet is a small physical device that stores cryptocurrency private keys offline. Coldcard is a Bitcoin-only hardware wallet made by Canadian firm Coinkite, designed to keep keys off internet-connected computers. The exploit traces to firmware 4.0.1's random-number handling, meaning devices using that code could generate weak, predictable seed phrases for years, contradicting the community's 'don't trust, verify' ideal.
Discussion
Reddit commenters were skeptical of Coinkite's denial, with one user outlining a supply-chain scenario in which a factory worker could pocket a wallet, record its seed, and later drain users who did not add a passphrase. The discussion reflected broader concern that the bug may be wider than initially disclosed and that users should add extra entropy or passphrases.
References
Tags
#Coldcard#hardware wallet#security#exploit#bug