A bug in hardware wallet randomness allows for key generation to be compromised, resulting in a loss of $38 million.
By Shaurya Malwa Jul 31, 2026, 5:12 a.m. 2 min readMake preferred on ShareShare this articleCopy linkX (Twitter)LinkedInFacebookEmailMake preferred on Coldcard vulnerability allows attackers to steal $38 million in bitcoin. (Coinkite)SummaryShow- A security flaw in some Coldcard hardware wallets allowed an attacker to steal approximately 594 bitcoin, valued at about $38 million, from around 500 single-signature wallets in just under half an hour.
- This vulnerability, introduced in Coldcard firmware version 4.0.0 in March 2021, caused devices to bypass their hardware randomness generator and revert to a predictable software-based key generation method using non-secret chip data.
- Coinkite has issued warnings to users who created seeds on Mk3 devices running firmware 4.0.1 or newer, while stating that Mk4, Q, and Mk5 models appear to be unaffected at this time, and the theft has had minimal impact on bitcoin's market value.
A total of 594 bitcoin, equivalent to around $38 million, was illicitly transferred from nearly 500 individual wallets between 01:31 and 01:56 UTC on Friday, attributed to a flaw in the key generation process of Coldcard hardware wallets.
The attack involved 1,324 separate bitcoin transactions completed within a three-block window, with 562 BTC later consolidated into a single address that remains inactive.
The compromised wallets were all single-signature types, each containing more than 0.15 BTC, many of which had been inactive for years, with their creation dates aligning closely with the identified flaw.
Coldcard is a hardware wallet manufactured by the Canadian company Coinkite, designed to securely store bitcoin keys offline, away from internet-connected devices. The models include Mk2, Mk3, Mk4, Q, and Mk5, released over time similar to smartphone models.
The risk is tied to the firmware version at the time the wallet was set up, not when the hardware was purchased.
Wallet seeds, the secret phrases that control access to funds, are intended to be generated randomly from an extensive pool, making them nearly impossible to guess.
However, Coldcard's firmware failed to implement this properly. According to a report from Block's Bitcoin engineering and security teams, a build setting directed the device to skip its own hardware randomness generator, while a check in a supporting library only verified the existence of that setting, not its activation.
This resulted in key generation reverting to a basic software method that relied on the serial number and clock registers of the chip.
These elements are not confidential; the serial number is fixed factory data, and the clock values can be measured by an attacker with access to a similar device. Block traced the issue back to a commit made on March 1, 2021, included in firmware version 4.0.0 released that month.
Consequently, Coinkite warned users who generated a seed on an Mk3 device running version 4.0.1 or newer, asserting that "Mk4, Q and Mk5 are not affected based on our early analysis."
Block disclosed its findings to Coinkite, which acknowledged the issue. Both companies regard their evaluations as preliminary, with Block stating it published the information without comprehensive testing to confirm the exploitability due to ongoing exploitation at the time.
The vulnerability extends beyond just wallet seeds; the same flawed generator also produced private keys for Coldcard's paper wallets, where the output directly forms the key without further processing, as well as seed-splitting masks, device cloning keys, and Key Teleport transfers.
Bitcoin was trading above $64,000 during early Asian hours, and the widespread theft did not appear to significantly affect the market.
Latest Crypto News- 1Bitcoin remains steady near $64,000 as Kospi's record 17% surge does not impact crypto16 minutes ago
- 2Strategy reports $8.2 billion loss in Q2 due to decline in bitcoin prices9 hours ago
- 3Coinbase falls 5% after failing to meet Q2 revenue forecasts9 hours ago
- 4Global banks trial tokenized currency for cross-border payments in $1 million BIS pilot12 hours ago
- 5Ondo Finance considers acquisition valued at up to $500 million13 hours ago
- 6Crypto for Advisors: Is the Clarity Act still viable?14 hours ago
- 7CME's Duffy warns of a looming tax risk concerning U.S. perpetual futures15 hours ago
- 8Examining the rationale behind Aave's proposal to abandon six chains yielding minimal revenue15 hours ago
- 9JPMorgan notes diminishing prospects for the Clarity Act affecting crypto sentiment15 hours ago
- 10Institutional trading reaches a record 72% as Wall Street stabilizes amid crypto volatility16 hours ago
Anvil: The Missing Collateral Layer
Anvil: The Missing Collateral Layer
Anvil is a shared on-chain collateral layer built on a programmable letter of credit: reserve assets as a guarantee -no loan, no interest, keep custody & yield.
By CoinDesk ResearchJul 29, 2026Commissioned byAnvilAnvil is a shared on-chain collateral layer built on a programmable letter of credit: reserve assets as a guarantee -no loan, no interest, keep custody & yield.
Why it matters:
Anvil is a shared on-chain collateral layer built on a programmable letter of credit: reserve assets as a guarantee -no loan, no interest, keep custody & yield.
View Full ReportMore From Tech