COLDCARD Wallet Firmware Flaw Triggers $88 Million Bitcoin Theft
A vulnerability in COLDCARD wallet firmware has possibly caused the exploitation of $88.6 million in Bitcoin due to issues in its random number generation. Users are urged to take immediate actions to secure their funds.

Introduction to the COLDCARD Vulnerability
A recent security vulnerability in the COLDCARD hardware wallet firmware has been linked to the theft of approximately $88.6 million in Bitcoin. According to Galaxy Research, a digital asset research firm, the theft exploited a flaw in the random number generator (RNG) used to create wallet seeds. The initial wave of theft, which occurred on July 30, 2026, drained about 1,083 BTC from nearly 1,200 addresses.
How the Attack Occurred
The hacking incident resulted in three distinct waves of theft, leading to a cumulative total of 1,367 BTC, worth approximately $88.6 million. The attack was notable for its speed, with the first wave occurring just over 30 hours before the vulnerability was disclosed by Coinkite. Researchers believe the attack involved automated tools, as every transaction utilized a uniform hardcoded fee rate of 30 satoshis per virtual byte and left no change output.
Details of the Vulnerability
In their investigation, researchers from Block, the engineering and security team, identified that the vulnerability stemmed from an integration error in the COLDCARD's RNG code. This flaw caused the system to use a deterministic software generator called Yasmarang, instead of the secure hardware RNG. The fallback generator’s reliance on the device's microcontroller identifier and system timing values compromised its randomness, making it susceptible to exploitation.
Impact of the Flaw
The compromised RNG allowed attackers to generate potential wallet seeds offline. Once they determined valid wallet addresses linked to the stolen Bitcoin, they could eventually match these with the generated seeds, acquiring the private keys required to access and transfer the funds. This breach is particularly severe given that affected wallet addresses had already been targeted, with reports indicating that $30 million was stolen within the first ten minutes of the attack.
Scope of Affected Devices
The COLDCARD devices affected by this flaw include those using Mk2 and Mk3 firmware versions 4.0.1 through 4.1.9, as well as Mk4 and Mk5 devices before standard version 5.6.0 and Edge versions 6.6.0X. The new firmware versions that fix this issue are 4.2.0 or later for Mk2 and Mk3, 5.6.0 or later for Mk4 and Mk5, and 1.5.0Q or later for standard Q devices.
Steps for Affected Users
For users with affected seed phrases, Coinkite recommends several urgent actions:
- Verify existing backups.
- Install the updated firmware.
- Generate a new seed and securely record it.
- Verify the new wallet address on the device.
- Conduct a small test transaction before transferring larger amounts.
It is crucial to retain backups of the old seeds until the migration is successfully completed and confirmed, as updating the firmware does not rectify any prior bad seeds.

Mitigating Risk
While Coinkite has informed users that seeds augmented with at least 50 fair, independent, and private dice rolls are not inherently at risk from this vulnerability, users are still encouraged to migrate to new seeds due to the flaws in the previous generation. Implementing strong unique BIP-39 passphrases can also offer an additional layer of protection.
Coinkite's Response
In response to the situation, Coinkite has destroyed all COLDCARD devices that were awaiting shipment with the compromised firmware. Customers who purchased devices already shipped were promptly contacted via email, providing them with security advisories and detailed instructions for migration to mitigate risks.
Conclusion
The vulnerability in the COLDCARD firmware underscores the importance of robust computational security measures in cryptocurrency storage. Users of affected devices are urged to take immediate action to safeguard their digital assets and stay informed about ongoing developments related to updates in COLDCARD functionality and security protocols.
Key Takeaways
- The COLDCARD firmware flaw likely led to the theft of $88.6 million in Bitcoin.
- Approximately 1,367 BTC were stolen from 4,585 addresses during the attack.
- Users must migrate from older seeds, especially those generated between specified firmware versions.
- New firmware versions address the RNG vulnerability, but previously generated seeds remain at risk.
Frequently Asked Questions
