Theme:
Light Dark Auto
GeneralPoliticsBusinessEconomyTechnologyEnvironmentSportsEntertainmentGeneral
BUSINESS
Negative Sentiment

Hackers Exploit Coldcard Flaw to Drain $110 Million in Bitcoin

Read, Watch or Listen

Media Bias Meter
Sources: 19
Center 100%
Sources: 19

Hackers have exploited a critical software vulnerability in Coldcard hardware wallets to drain more than 1,755 Bitcoins worth approximately $110 million from roughly 5,000 wallets in an ongoing attack. Coldcard devices, manufactured by Canada-based Coinkite Inc., are specialized hardware units designed to keep cryptocurrency offline in cold storage, isolated from internet connectivity. According to on-chain data mapped by Galaxy Research, the attack escalated rapidly over several days. Initial breaches reported on July 30 accounted for 594 Bitcoins worth about $38 million swept from 500 addresses. Losses expanded to $70 million across 1,082 Bitcoins by August 1, reached $89 million across 1,367 Bitcoins by August 2, and passed $110 million across 1,755 Bitcoins by Monday, August 3. Engineering teams from Block Inc. identified the root cause as a defect in how Coinkite implemented random-number generation during wallet creation. The vulnerability traces back to a March 2021 firmware release, version 4.0.1, affecting Mk3 devices through firmware version 5.0.3. Instead of using the hardware true random-number generator, affected firmware routed seed phrase creation through a software pseudorandom generator. The generator relied on predictable, deterministic inputs, including device serial numbers and internal clock states. This allowed external attackers to systematically recalculate potential master seed phrases offline and reconstruct private keys without ever gaining physical access to the devices. "It exposes the fallacy of your crypto being offline," said Aneirin Flynn, chief executive officer of cybersecurity firm Failsafe. "The device is just responsible for generating your passwords, and if the underlying math is broken then your passwords can be reverse-engineered." Victims reported that funds were swept automatically without any phishing interaction or physical compromise. Individual investor Jonathan Goodman stated that $1.6 million in Bitcoin wa

Prepared by Christopher Adams and reviewed by editorial team.

Timeline of Events

  • On March 15, 2021 Coinkite released firmware version 4.0.1 introducing the flaw.
  • On July 30, 2026 Hackers drained 594 bitcoins worth 38 million in minutes.
  • On July 31, 2026 Coinkite issued advisory warning users about vulnerable seed generation.
  • On August 1, 2026 Galaxy Research mapped losses expanding to 70 million dollars.
  • On August 2, 2026 Cumulative tracked losses climbed to 89 million across addresses.
  • On August 3, 2026 Total drained funds surpassed 110 million across 5000 wallets.
  • On August 3, 2026 Block Inc engineers confirmed software pseudorandom generator root cause.
  • In coming months, affected users will complete migrations to new wallets.
  • In coming years, hardware wallet supply chain security will face scrutiny.
  • In the long term, zero trust cryptographic practices will reshape storage

News Intelligence

  • US crypto holders face urgent security audits and immediate asset migration.
  • Self custody models will undergo permanent structural risk management evaluation.
  • Individual cryptocurrency investors holding hardware wallets across US financial hubs.
  • Prioritize verified vendor disclosures over social media speculation and alerts.
Media Bias
Articles Published:
19
Right Leaning:
0
Left Leaning:
0
Neutral:
19

Explain Framing

Left: Highlighted systemic regulatory failures and risks in unregulated cryptocurrency storage. Center: Reported technical facts regarding firmware flaws and on-chain fund movements. Right: Emphasized individual user responsibility and risks within self custody models

Original Source

Coinkite security advisory regarding firmware vulnerability and seed generation risks on July 30, 2026. Direct URL to the original triggering source, where available but only 1: https://blog.blockstream.com/jade-unaffected-coldcard-vulnerability/

Media Bias
Articles Published:
19
Right Leaning:
0
Left Leaning:
0
Neutral:
19
Distribution:
Left 0%, Center 100%, Right 0%
Explain Framing

Left: Highlighted systemic regulatory failures and risks in unregulated cryptocurrency storage. Center: Reported technical facts regarding firmware flaws and on-chain fund movements. Right: Emphasized individual user responsibility and risks within self custody models

Original Source

Coinkite security advisory regarding firmware vulnerability and seed generation risks on July 30, 2026. Direct URL to the original triggering source, where available but only 1: https://blog.blockstream.com/jade-unaffected-coldcard-vulnerability/

Coverage of Story:

Related News

Comments

JQJO App
Get JQJO App
Read news faster on our app
GET