A flaw in COLDCARD hardware wallet firmware likely let attackers steal about $88.6 million in Bitcoin from thousands of wallets. Researchers say an integration error caused affected devices to use a deterministic software random number generator instead of the STM32 hardware random number generator when creating wallet seeds, making seeds guessable offline. Coinkite says affected versions include Mk2 and Mk3 firmware 4.0.1 through 4.1.9, Mk4 and Mk5 before 5.6.0 or 6.6.0X, and Q devices before 1.5.0Q or 6.6.0QX; patching does not fix already generated seeds.
Why it matters: This is both a vulnerability and an active theft event affecting cryptocurrency holders, and updating alone is not enough if a seed was created on a vulnerable version. Affected users should install fixed firmware, generate a new seed, and move funds after testing the new wallet.
Lawrence Abrams
2026.08.05
72% relevant
This article describes follow-on phishing attacks directly leveraging the same COLDCARD wallet incident and the reported $88.6 million Bitcoin theft, adding that attackers are impersonating COLDCARD, using fake audit emails and websites, and installing ConnectWise ScreenConnect via a malicious batch file.
2026.08.03
96% relevant
This article updates the same Coldcard theft event with new details that Coinkite destroyed remaining inventory built with the vulnerable firmware, halted shipments, released patched firmware, and told affected users to retain devices for possible recovery efforts.
Lawrence Abrams
2026.08.02
100% relevant
This article appears to be the first clear report in the set tying a specific COLDCARD firmware random-number-generation flaw to real-world wallet drains and quantifying the theft impact.
← Back to all stories