Particle.news
Download on the App Store

Coldcard Firmware Bug Leads to Theft of Roughly $116 Million in Bitcoin

A build-time flag disabled Coldcard’s hardware random-number generator, producing enumerable seeds that let attackers derive private keys.

Overview

  • Security researchers and Coinkite say attackers began sweeping addresses created on affected Coldcard devices on July 29–30, 2026, draining thousands of single-signature wallets.
  • The root cause was a 2021 firmware build setting that skipped the dedicated hardware RNG and fell back to a software seed tied to chip serial and clock values, collapsing entropy into a searchable space.
  • Blockchain analysts and firms reported roughly 1,500–1,816 BTC stolen, a loss valued at about $116–$140 million with some estimates of higher totals as sweeps continued.
  • Coinkite has publicly acknowledged the flaw, issued emergency firmware and guidance, destroyed remaining vulnerable stock, and is helping customers while its technical review and investigations continue.
  • The incident prompted mass user migrations to custodial services and renewed calls for multi-signature setups, strong passphrases, and stricter firmware build and audit controls for anyone holding large sums of bitcoin.