#1
The Hacker News
general
August 01, 2026 at 17:17 UTC
Coldcard Hardware Wallet Flaw Linked to $70 Million Bitcoin Theft in 41 Minutes
By [email protected] (The Hacker News)
AI Summary
A firmware flaw in Coldcard hardware wallets — introduced via a March 2021 firmware integration error that routed seed generation to a deterministic software PRNG — enabled an attacker to drain 1,196 Bitcoin addresses in just 41 minutes on July 30, stealing 1,082.65 BTC (~$70.2M). Galaxy Research performed the forensic sweep and attributed the exploit to Coinkite's Coldcard device. This is a critical finding for anyone relying on hardware wallets for custody security, as it demonstrates that supply-chain-level firmware bugs can silently compromise cryptographic key generation.
Relevance score: 92.0/100
Sponsored
Protect Your Business
Expert cybersecurity solutions to safeguard your organization from evolving threats.
Get Protected →