Hackers have exploited a critical software vulnerability in Coldcard hardware wallets to drain more than 1,755 Bitcoins worth approximately $110 million from roughly 5,000 wallets in an ongoing attack. Coldcard devices, manufactured by Canada-based Coinkite Inc., are specialized hardware units designed to keep cryptocurrency offline in cold storage, isolated from internet connectivity. According to on-chain data mapped by Galaxy Research, the attack escalated rapidly over several days. Initial breaches reported on July 30 accounted for 594 Bitcoins worth about $38 million swept from 500 addresses. Losses expanded to $70 million across 1,082 Bitcoins by August 1, reached $89 million across 1,367 Bitcoins by August 2, and passed $110 million across 1,755 Bitcoins by Monday, August 3. Engineering teams from Block Inc. identified the root cause as a defect in how Coinkite implemented random-number generation during wallet creation. The vulnerability traces back to a March 2021 firmware release, version 4.0.1, affecting Mk3 devices through firmware version 5.0.3. Instead of using the hardware true random-number generator, affected firmware routed seed phrase creation through a software pseudorandom generator. The generator relied on predictable, deterministic inputs, including device serial numbers and internal clock states. This allowed external attackers to systematically recalculate potential master seed phrases offline and reconstruct private keys without ever gaining physical access to the devices. "It exposes the fallacy of your crypto being offline," said Aneirin Flynn, chief executive officer of cybersecurity firm Failsafe. "The device is just responsible for generating your passwords, and if the underlying math is broken then your passwords can be reverse-engineered." Victims reported that funds were swept automatically without any phishing interaction or physical compromise. Individual investor Jonathan Goodman stated that $1.6 million in Bitcoin wa
Prepared by Christopher Adams and reviewed by editorial team.
Izquierda: Fallos regulatorios sistémicos y riesgos destacados en el almacenamiento de criptomonedas no regulado. Centro: Hechos técnicos informados sobre fallos de firmware y movimientos de fondos en la cadena. Derecha: Se enfatizó la responsabilidad del usuario individual y los riesgos dentro de los modelos de autocustodia.
Coinkite aviso de seguridad sobre vulnerabilidad de firmware y riesgos de generación de semilla el 30 de julio de 2026. URL directa a la fuente original que desencadenó, cuando esté disponible, solo 1: https://blog.blockstream.com/jade-unaffected-coldcard-vulnerability/
No left-leaning sources found for this story.
Hackers Exploit Coldcard Flaw to Drain $110 Million in Bitcoin
Insurance Journal / Bloomberg Cointelegraph The Hacker News Blockstream Blog MyBroadband CyberInsider The Hacker News IG PYMNTS Bitcoin Well Infosecurity Magazine Medium (The Prediction Market Intelligence) The Straits Times CoinDesk Blockaid Security Blog Decrypt Bloomberg TRM Insights Galaxy ResearchNo right-leaning sources found for this story.
Comments