Coldcard Firmware Flaw Linked to Theft of More Than 1,000 Bitcoin
Hardware wallet maker Coinkite confirmed on July 30, 2026 that a firmware bug weakened the way several Coldcard models generate wallet seeds. On the same day, roughly 594.48 Bitcoin were swept from about 500 wallets within a window of only a few blocks. Blockchain analysts have since linked a total of about 1,082 Bitcoin, worth roughly 70 million dollars, to the same signature.
The primary source for this report is Coinkite's own security advisory, published July 30 and updated August 1.
What happened
According to on-chain analysis first shared by AnchorWatch chief executive Rob Hamilton, 1,324 unspent outputs were consolidated across 500 transactions inside a three block window, totalling 594.48 Bitcoin. About 562 Bitcoin were then moved again to a single new address, which has not moved the funds since.
The drained outputs dated from 2021 to 2026. Every affected address was single signature, and none used Taproot. Clay Garrett, engineering lead for Block's Bitkey wallet, later identified 695 earlier transactions carrying the same fingerprint, moving another 488.11 Bitcoin. If they belong to the same operator, the combined total reaches about 1,082.59 Bitcoin.
Chainalysis reported that the attacker drained the highest value wallets first, including one holding about 1.8 million dollars, and that roughly 30 million dollars left in the first ten minutes before the remaining wallets were emptied.
What Coinkite confirmed
Coinkite traced the cause to seed generation that relied on a software random number generator instead of the intended hardware source. The company estimates the effective search space at about 40 bits on the Mk2 and Mk3, and about 72 bits on the Mk4, Mk5 and Q, against the 128 bit target for a twelve word seed.
The advisory names the affected seed generation as follows.
| Model | Affected seed generation |
|---|---|
| Coldcard Mk2 and Mk3 | Firmware 4.0.1 through 4.1.9 |
| Coldcard Mk4 and Mk5 | Before standard firmware 5.6.0 (Edge before 6.6.0X) |
| Coldcard Q | Before standard firmware 1.5.0Q (Edge before 6.6.0QX) |
Coinkite says Tapsigner, Opendime and Satscard are not affected, because they use different codebases. The company also states that a seed created with at least fifty independent, private dice rolls is not considered at risk from this issue alone.
Coinkite has released fixed firmware for every affected model, including version 4.2.0 for the Mk2 and Mk3. An earlier changelog had said the company did not plan to update the Mk3 at that time, a position it has since reversed.
What Coinkite advises
Coinkite states that a firmware update does not repair a seed that was already generated by affected firmware, and that reimporting the same seed onto a new device does not help either, because the weakness lives in the seed itself. The company advises affected users to update the firmware, generate a completely new seed, verify the backup and a receive address, send a small test transaction, and then migrate the remaining funds.
A trail to a data provider
Block's security team reported that the operator used a paid account at a well known blockchain services provider to query the source addresses and carry out related steps during the sweeps. According to Garrett, the provider's internal logs matched the number, timing and order of the requests seen on chain. Block says it found no evidence that the provider knowingly assisted the theft, and that it has forwarded its findings to law enforcement.
Coinkite added that it assumes someone used an AI model to review its publicly available firmware and found the flaw. The company said it had run one of the best available AI models over its own code a few weeks earlier, and that the review did not surface the bug.
CanoeBit's companion analysis explains how the bug reached the firmware, why a weak seed cannot be repaired, and what the case means for the wider "airgapped equals secure" narrative.
Sources
- 1.Coinkite: Technical Deep Dive into the Entropy Issue
- 2.Coinkite: Coldcard Security Advisory (Mk2/Mk3 seed generation warning)
- 3.Block Engineering: Predictable RNG Fallback and 32-Bit Reseed in Coldcard Firmware
- 4.The Block: Bitcoin losses linked to Coldcard vulnerability grow to $70 million, Galaxy Research says
- 5.CoinDesk: How bitcoin cold wallets lost $70 million in an attack that never touched the devices
- 6.Bitcoin Magazine: Coldcard Bitcoin thief likely used top blockchain-services provider
Not financial advice. CanoeBit publishes educational content only. Nothing here is a recommendation to buy, sell, or hold any asset.