Swing To Trade
  • Stock
  • Politics
  • Business
  • Investing
Stock

Coldcard Flaw Blamed for $38 Million Bitcoin Theft From 500…

by admin July 31, 2026
July 31, 2026

How Did The Coldcard Attack Drain 594 Bitcoin?

Roughly 594 bitcoin worth about $38 million was removed from around 500 wallets early Friday in an attack linked to weak key generation in certain Coldcard hardware wallet firmware versions.

The theft occurred between 01:31 and 01:56 UTC, with the attacker moving 1,324 portions of bitcoin across 500 transactions within three Bitcoin blocks. About 562 BTC was later consolidated into a single address that had not moved at the time of reporting.

Every drained wallet used a single-signature setup and held more than 0.15 BTC. Many of the wallets had remained inactive for years, while the stolen coins dated from 2021 through 2026, closely matching the period during which the vulnerable firmware was available.

Bitcoin continued trading above $64,000 during early Asian hours, suggesting that the theft had little immediate effect on the wider market. The incident instead created a direct security risk for Coldcard users whose wallet seeds were generated with affected firmware.

What Went Wrong With Coldcard’s Key Generation?

Coldcard is a bitcoin-only hardware wallet produced by Canadian manufacturer Coinkite. Its Mk2, Mk3, Mk4, Q and Mk5 devices are separate generations designed to create and store private keys away from internet-connected computers.

A wallet seed should be generated from enough random information that an attacker cannot realistically recreate it. Block’s Bitcoin engineering and security teams found that a firmware build setting caused affected Coldcard devices to bypass their hardware random-number generator.

A supporting software library checked only whether that setting existed, rather than whether it was enabled. The device then relied on a weaker software substitute seeded with the chip’s serial number and internal clock registers.

Those inputs are not secret. A serial number is fixed device metadata, while clock values can potentially be narrowed down through timing analysis or testing on similar hardware. An attacker able to reconstruct those inputs could reduce the number of possible wallet seeds enough to identify vulnerable addresses and steal the funds.

The change was traced to code dated March 1, 2021, and was introduced in firmware released that month. Exposure depends on the firmware running when the wallet seed was created, not when the Coldcard device was purchased or whether the seed was later imported into another wallet.

Investor Takeaway

Updating the device does not repair a seed that was generated with weak randomness. Affected users need to create a new seed with fixed software and move their bitcoin to addresses controlled by that new seed.

Which Coldcard Users May Still Be Exposed?

Coinkite initially warned users who created seeds on an Mk3 running firmware version 4.0.1 or later. Early analysis said Mk4, Q and Mk5 devices were not affected, but later guidance warned that seeds generated on those models before the relevant firmware fixes may also face risk.

Both Coinkite and Block described their findings as preliminary. Block said it disclosed the issue to Coinkite and published before completing full exploitability testing because wallet draining was already taking place.

The problem may extend beyond standard recovery phrases. The same weak generator was reportedly used for Coldcard paper-wallet private keys, seed-splitting masks, device-cloning keys and Key Teleport transfers. Paper wallets may face greater exposure because the generated output can become the private key directly without another derivation step.

Users who imported a vulnerable Coldcard seed into another hardware or software wallet remain exposed. Moving the same seed to a Trezor, Blockstream, Foundation, Tangem or another device does not create new private keys. Funds remain controlled by the original compromised seed until they are sent to a newly generated wallet.

What Does The Theft Mean For Hardware Wallet Security?

The attack shows that keeping keys offline cannot protect funds when the keys themselves were created with predictable inputs. Hardware wallets reduce exposure to malware and remote theft, but their security still depends on correct firmware, trustworthy random-number generation and careful review of cryptographic code.

Coinkite said it had been unaware of the bug and suggested that an attacker may have used an advanced artificial intelligence model to examine older open-source firmware. There is no public evidence confirming that AI was used, and the company also acknowledged that its own recent AI-assisted review did not detect the flaw.

The incident may increase scrutiny of open-source hardware wallet code, software build settings and independent security audits. It also strengthens the case for multisignature storage when holding large amounts of bitcoin.

A multisignature wallet can require two of three separate keys to approve a transaction. Using devices from different manufacturers reduces the chance that one firmware defect will expose every key needed to move the funds.

Coldcard users now face two questions: whether their seed was created with affected firmware and whether the attacker is still identifying vulnerable wallets. The confirmed theft has stopped moving for now, but unchanged funds remain at risk if their private keys were generated through the same flawed process.

previous post
IRS Warns Crypto Holders About Fake Letters Seeking Assets…
next post
Wanchain Gives Hacker Until 12:00 UTC on August 6 to Return…

Related Posts

Strategy Says It Will Continue Selling Bitcoin and...

July 31, 2026

Bitcoin Is Back at $65,000—and Investor Sentiment Has…

July 31, 2026

Wanchain Gives Hacker Until 12:00 UTC on August...

July 31, 2026

IRS Warns Crypto Holders About Fake Letters Seeking...

July 31, 2026

Samsung and Upbit Operator Discuss AI-Based Payments and…

July 30, 2026

Aave Proposal Targets $98 Million in Assets Across...

July 30, 2026

Bitcoin ETFs Took In $205 Million This Month....

July 30, 2026

South Korea to Tax Annual Crypto Profits Above...

July 30, 2026

Pump.fun Graduation Rate Jumps Eightfold After BOOST Launch

July 30, 2026

Tether’s US-Regulated Stablecoin Just Left Ethereum…

July 30, 2026
Join The Exclusive Subscription Today And Get Premium Articles For Free

    Your information is secure and your privacy is protected. By opting in you agree to receive emails from us. Remember that you can opt-out any time, we hate spam too!

    Recent Posts

    • Strategy Says It Will Continue Selling Bitcoin and No…

      July 31, 2026
    • Bitcoin Is Back at $65,000—and Investor Sentiment Has…

      July 31, 2026
    • Wanchain Gives Hacker Until 12:00 UTC on August 6 to Return…

      July 31, 2026
    • Coldcard Flaw Blamed for $38 Million Bitcoin Theft From 500…

      July 31, 2026
    • IRS Warns Crypto Holders About Fake Letters Seeking Assets…

      July 31, 2026
    • Privacy Policy
    • Terms & Conditions

    Copyright © 2026 SwingToTrade.com All Rights Reserved.

    Swing To Trade
    • Stock
    • Politics
    • Business
    • Investing