Overview
- Researchers and Coinkite say a March 17, 2021 firmware change caused some Coldcard devices to fall back to a weak software pseudorandom generator, reducing seed entropy and making those recovery seeds predictable.
- Attackers began coordinated on‑chain sweeps on July 30–31, 2026 that drained over 1,000 BTC in minutes and later waves raised linked losses to about 1,778–1,800+ BTC, worth roughly $112–$118 million by recent estimates.
- Coinkite issued emergency patches at the end of July but warned that installing updated firmware does not secure any seeds already generated on vulnerable builds, so users must generate new seeds on patched devices and migrate funds.
- Investigators traced operational metadata from the first-wave sweep to queries made from a paid blockchain‑data account and say the first attacker’s identity may be known to law enforcement, though no public arrest, charge, or recovery has been announced.
- Analysts say multisignature wallets were not compromised and the episode highlights weaknesses in vendor governance and the asymmetric ease of finding one exploitable path versus defending every possible weakness, a gap researchers say was amplified by available AI tooling.