Coldcard flaw exploited to steal 1,367 BTC, about $89 million
AI مارکیٹ کا خلاصہ
A long-standing Coldcard firmware entropy bug enabled attackers to drain ~1,367 BTC (~$89M) from 4,500+ addresses, highlighting operational and custody risk around self-custody hardware wallets. While Coinkite shipped rapid patches, affected users must migrate to new seeds, leaving near-term uncertainty for compromised funds. The incident can pressure market confidence and raise scrutiny of wallet security practices across the Bitcoin ecosystem.
اثر کی سطح
● ہائی
متاثرہ اثاثے
BTC/USDT+0.78%
AI تجزیاتی سمجھ · BTC/USDTAI تجزیاتی سمجھ
▼ Bearish
ابھی ٹریڈ کریں
⚠️ AI سے تیار کردہ تجزیاتی سمجھ خبروں کے مواد پر مبنی ہے اور صرف معلوماتی مقاصد کے لیے فراہم کی گئی ہے۔ یہ سرمایہ کاری کا مشورہ نہیں ہے اور نہ ہی BingX کے خیالات کی نمائندگی کرتی ہے۔ سرمایہ کاری میں رسک شامل ہے۔ براہ کرم ذمہ داری سے ٹریڈ کریں۔
A weakness in Coldcard hardware wallets has been exploited to steal about 1,367 BTC—roughly $89 million—from more than 4,500 addresses since coordinated attacks began on July 30.
The issue traces back to a firmware bug that entered production in March 2021. It undermined the randomness used to create wallet "seeds", ultimately allowing attackers to crack affected seeds and drain funds.
How the firmware flaw reduced seed security
When a hardware wallet is initialized, it generates a seed—the master key controlling the Bitcoin stored in the wallet. Security depends on that seed being truly random. The industry benchmark is 128 bits of entropy, a level intended to make brute-force guessing infeasible on any realistic timescale.
Coldcard firmware version 4.0.1, released in March 2021 by Canadian maker Coinkite, introduced the defect during a major rewrite. On impacted devices—specifically Mk2 and Mk3 models—seeds were generated with about 72 bits of entropy instead of 128.
That gap is not marginal. Every bit of missing entropy halves the number of possibilities. A reduction of 56 bits shrinks the search space by roughly 72 quadrillion, turning what would normally be a theoretical risk into an exploitable one.
Timeline: attack activity and patch rollout
Attackers began exploiting the weakness on July 30, 2026. Within days, about 1,367 BTC had been siphoned from wallets whose seeds were created on the vulnerable firmware, with the stolen amount valued near $89 million at the time.
The rapid draining across more than 4,500 addresses suggests advance preparation, potentially including precomputation of vulnerable seeds before executing thefts in quick succession.
Coinkite issued patched firmware on July 31, one day after the attacks became evident. Updates were released as version 5.6.0 for Mk4 and Mk5 devices, version 1.5.0Q for the Q model, and version 4.2.0 for the older Mk3.
Firmware updates alone are not enough
Applying the patch does not retroactively secure compromised seeds. Users who created seeds on affected firmware versions still need to migrate funds to entirely new seeds; the old seeds remain vulnerable regardless of the device's current firmware.
Seeds generated using at least 50 independent fair dice rolls were not impacted, since they did not rely on the device's internal random number generator. Seeds created on firmware versions earlier than 4.0.1 were also unaffected. The flaw was limited to the entropy-generation code introduced in the 2021 rewrite.
Open-source debate resurfaces
Foundation Devices CEO Zach Herbert cited the open-source nature of Bitcoin wallet code as a key reason the community was able to identify the issue and respond quickly. He argued that proprietary firmware would likely have delayed detection and complicated remediation.
Herbert's company makes the Passport hardware wallet, which competes directly with Coldcard. The vulnerability remained in shipping firmware for more than five years before being actively exploited, while the one-day turnaround from visible attack to patch highlights how transparent codebases can accelerate incident response.
What users should do now
Coldcard users with seeds generated after March 2021 should update firmware immediately and, more importantly, create new seeds and migrate funds. Updating firmware without moving to a new seed leaves the core exposure unresolved. Users who used at least 50 independent fair dice rolls for seed generation are not affected.