< Back to all clusters
[TECHNOLOGY] · Canada, United States, Australia, Thailand, Colombia · 8 sources

Coldcard hardware wallet flaw leads to $130 million Bitcoin theft

A firmware bug introduced in March 2021 in Coldcard hardware wallets (models Mk2‑Q) weakened the random‑number generator, reducing seed‑phrase entropy from 128 bits to about 40 bits. The flaw allowed attackers to reconstruct recovery phrases without physical access.

The exploit began on 30 July 2026 and unfolded in several rapid waves. Researchers estimate that between 1,596 and 2,055 BTC (roughly $130 million) were stolen from more than 7,300 compromised wallets. The largest single haul, 1,159 BTC, is held in seven attacker‑controlled addresses that have not moved. A separate attacker obscured about 64 BTC through the Wasabi CoinJoin mixer.

Geographically, Canadian Bitcoin holders absorbed about 25 % of the $116 million loss, with Australia, the United States and Thailand also heavily affected. Individual victims reported losses such as a CAD 1.6 million theft from a Coldcard device. Coinkite, the wallet’s manufacturer, issued firmware version 4.2.0 to fix the RNG issue and urged all users to generate new seed phrases and migrate funds.

Entities: Bitcoin · CertiK · Coinkite · Coldcard (Coinkite) · Coldcard hardware wallet · Galaxy Research · Jameson Lopp · Wasabi Wallet

Claims

What the coverage asserts, and how well corroborated each claim is across sources.

  • [● 5 SOURCES] A firmware bug introduced in March 2021 in Coldcard devices reduced seed‑phrase entropy from 128 bits to about 40 bits. (The flaw was introduced in March 2021 and weakened the RNG, lowering entropy to 40 bits.)
  • [● 3 SOURCES] Between 1,596 and 2,055 BTC, worth about $130 million, were stolen in the Coldcard attack. (Loss estimates range from 1,596 to 2,055 BTC (~$130 million).)
  • [○ 1 SOURCE] Canadian Bitcoin holders accounted for about 25 % of the total $116 million loss. (Canada represented 25 % of attributable losses, totalling $116 million.)
  • [● 2 SOURCES] More than 7,300 Coldcard wallets were compromised in the exploit. (Over 7,300 wallets were affected.)
  • [● 2 SOURCES] Coinkite released firmware version 4.2.0 to fix the RNG vulnerability and urged users to generate new seed phrases. (Version 4.2.0 patches the bug; users should create new seeds.)
  • [○ 1 SOURCE] The largest single theft involved 1,159 BTC held across seven attacker‑controlled addresses that have not moved. (1,159 BTC is held in seven addresses with no outgoing transactions.)
  • [● 2 SOURCES] The Coldcard exploit began on 30 July 2026 and unfolded in multiple rapid theft waves. (The attack started on 30 July 2026 and proceeded in several waves.)
  • [○ 1 SOURCE] Approximately 64 BTC were moved through the Wasabi Wallet mixer after the Coldcard breach. (Around 64 BTC passed through Wasabi CoinJoin mixing.)