A firmware flaw in Coldcard hardware wallets enabled an attacker to drain 1,196 Bitcoin addresses in 41 minutes on July 30, stealing 1,082.65 BTC worth about $70.2 million. Galaxy Research and Block linked the incident to a deterministic PRNG bug in Coinkite’s Coldcard firmware, which could allow offline seed reconstruction from constrained device data. #Coldcard #Coinkite #GalaxyResearch #Block
Keypoints
- An attacker drained 1,196 Bitcoin addresses in 41 minutes.
- Galaxy Research tied the sweep to a Coldcard firmware flaw.
- The bug caused seed generation to use a deterministic software PRNG instead of hardware RNG.
- Coinkite released emergency firmware, but affected seeds must be regenerated and funds moved.
- Older Coldcard models and firmware versions before the fixed releases were exposed.
Read More: https://thehackernews.com/2026/08/coldcard-hardware-wallet-flaw-linked-to.html