Hackers Hit Bitcoin’s Safest Hiding Place in Ongoing Attack
Researchers said the flaw reduced seed entropy to as little as 40 bits and let attackers drain more than $88 million without touching the devices.
- On July 30, 2026, attackers exploited a Coldcard firmware vulnerability to drain roughly 1,367 Bitcoin worth about $86 million from over 4,500 addresses across multiple waves, according to Galaxy Research.
- A March 1, 2021 firmware commit caused Coldcard devices to bypass their hardware random number generator, forcing them to rely on predictable software-based randomness instead, drastically reducing seed entropy.
- Block's security team identified a coding error in a supporting library that checked only whether a setting existed rather than whether it was enabled, allowing the flaw to persist undetected in open code for over four years.
- Coinkite released emergency firmware on July 31, but the company warned that updating does not secure existing seeds; users must generate entirely new seeds on patched devices and migrate funds.
- The incident reignited debates over self-custody risks, with Bitcoin security company Casa CEO Nick Neuman urging users to spread funds across multiple wallets to mitigate single-point-of-failure vulnerabilities.
96 Articles
96 Articles
The hackers carried out one of the largest attacks on Coldcard's hardware kryptos, and because of their critical vulnerability, they have already gained access to more than 4.5 thousand devices and stole bitcoins worth about $86 million.
'I'm Done With Bitcoin': $126,720 Gone Overnight, Eight Years of Saving Wiped Out in Coldcard Hack
Bitcoin investors were taken aback after Coldcard wallets created by Canada-based Coinkite, designed to function as a BTC-only hardware cold wallet to help store BTC private keys offline, were breached. Multiple media outlets and security experts mapped the attack and linked it to a firmware flaw in Coldcard, which was exploited to drain 1,196 BTC addresses in 41 minutes on 30th July, stealing over 1,082.65 BTCs worth over $70 million. Some expe…
After a software error with the Canadian provider of a storage medium, hackers exploit Bitcoins worth 86 million dollars.
Hackers hit Bitcoin’s safest hiding place in ongoing attack
Hackers exploited a software flaw in Coldcard Bitcoin wallets, causing significant financial losses. This vulnerability affected the security keys used to protect user cryptocurrency holdings. Millions of dollars have been siphoned from thousands of compromised wallets globally. The flaw involved a predictable seed phrase generation mechanism within the devices. Coinkite has released updated firmware to address the ongoing security breach.
Coverage Details
Bias Distribution
- 48% of the sources are Center
Factuality
To view factuality data please Upgrade to Premium























