Coldcard Hardware Wallet Firmware Flaw Linked to $70M Bitcoin Theft in 41 Minutes
One flaw, 41 minutes, seventy million dollars. Galaxy Research tied a July 30 sweep of 1,196 Coldcard-generated Bitcoin addresses to a 2021 firmware error that routed seed generation to a predictable software PRNG. What hardware-wallet owners should verify now.
An attacker emptied 1,196 Bitcoin addresses in 41 minutes and walked away with 1,082.65 BTC — about $70.2 million at the time of the theft. The addresses had something in common: the seeds behind them were generated on a Coldcard hardware wallet running firmware with a flaw that had been sitting in the field since March 2021.
On July 30, 2026, that flaw stopped being theoretical. Galaxy Research mapped the sweep and tied it to a firmware integration error that quietly replaced the one thing a hardware wallet exists to protect: the randomness behind your private keys. The Hacker News reported the theft and the root-cause finding. The takeaway for anyone holding a Coldcard isn't panic — it's a version check and, for some, a migration.
What Galaxy Research Traced
The event itself was fast and mechanical. In a single 41-minute window, an attacker drained 1,196 separate Bitcoin addresses of a combined 1,082.65 BTC. This wasn't a slow drip or a targeted grab of one whale's stash. It was a batch operation — the signature of someone who already knew, in advance, which keys they could reconstruct.
Galaxy Research mapped the on-chain activity and connected the drained addresses back to a common origin: seeds produced by Coldcard, the Bitcoin-only hardware wallet made by the Canadian firm Coinkite. That mapping is the load-bearing claim here. The money moving on-chain is public and verifiable; the meaningful analysis is the link from a scattered set of victim addresses to one shared point of failure in how those addresses were created.
The scale matters because of what it implies. Sweeping 1,196 addresses in well under an hour is only possible if the attacker didn't have to break each wallet individually. They had to break the process that generated all of them at once.
A Five-Year-Old Error in the One Number That Matters
A hardware wallet has one core job. It generates a seed — the master secret every one of your keys and addresses is derived from — using entropy from a true hardware random source, so that seed is, for all practical purposes, unguessable. Everything else the device does is secondary to getting that one number right.
According to the reporting, a March 2021 firmware integration error routed seed generation to a deterministic software pseudo-random number generator (PRNG) instead. A deterministic PRNG produces output that follows from its inputs. When it stands in for a genuine hardware random source, the “random” seed stops being random in the way that counts — it becomes predictable to anyone who understands how it was produced. Seeds that owners believed were drawn from physical entropy were, in fact, enumerable.
That is the whole story compressed into one sentence: the security of the wallet was never bypassed at the device level on July 30. It was undermined years earlier, at the moment those wallets first created their seeds. The theft is the delayed detonation of a 2021 defect.
● HOW A PREDICTABLE SEED HAPPENS A hardware wallet's whole security rests on an unguessable random seed. One 2021 integration error replaced the randomness. |
INTENDED — HARDWARE TRNG The device draws entropy from a true hardware random source, so each wallet seed is practically unguessable. |
| ↓ |
MARCH 2021 — DETERMINISTIC PRNG A firmware integration error routed seed generation to a deterministic software PRNG, making the "random" seed predictable. |
| ↓ |
JULY 30, 2026 — 41-MINUTE SWEEP 1,196 addresses drained of 1,082.65 BTC (~$70.2M) as predictable seeds were swept at scale. |
Source: The Hacker News; Galaxy Research. |
What Coldcard Owners Should Do Now
If you hold a Coldcard, treat this as a version-and-provenance problem, not a lost cause. The question isn't “is my device compromised” — it's “was my seed generated by firmware that could have used the deterministic PRNG.” Work through these steps in order:
- Verify your firmware version. Check exactly which firmware release your device is running and which version it was running when you first generated your seed. That generation event is what matters, not what's installed today.
- Assume exposure for any seed created on affected firmware. If your seed was generated during the window in which the deterministic-PRNG error was live, treat the funds behind it as at risk, whether or not they've moved.
- Migrate funds off any potentially affected address. Don't keep balances on addresses derived from a suspect seed. Move them.
- Generate a fresh seed on firmware known to use the hardware TRNG. A new seed produced by firmware confirmed to draw from the true hardware random source is the destination. Updating firmware does not retroactively fix a seed that was already created with predictable entropy — a bad seed stays bad, so the fix is a new seed plus a move of funds, not a patch alone.
- Watch for the vendor's official guidance. Track Coinkite's channels for a formal advisory, an affected-version list, and any recall or exchange-blacklist coordination, and act on the specifics when they land.
The order is deliberate: confirm the version, assume the worst for anything in the affected window, then move funds to a clean seed. Speed matters more than certainty here, because the attacker's economics reward doing this before you do.
The CyberSignal's Assessment: The Trust Model Held, the Supply Chain Didn't
My read: this is not a case for abandoning hardware wallets. The device's isolation model — keys generated and held offline, never exposed to an internet-connected machine — did exactly what it's supposed to. Nothing here suggests an attacker reached into the device over a network or extracted a key from silicon.
The failure was upstream, in the firmware supply chain, and it's the more unsettling kind. A single integration change altered the quality of the randomness feeding seed generation, and that change survived in shipped firmware for years without being caught. Cold storage protects you from the threats you can see — malware, phishing, a compromised laptop. It does nothing if the secret was born predictable.
The CyberSignal's assessment is that the durable lesson is about verifiability, not brand. The strength of a hardware wallet's entropy is the hardest property for an ordinary owner to check and the most catastrophic to get wrong. If a defect can hide in that layer for five years, then “trust the device” has to be paired with independent scrutiny of how seeds are generated — open review of the entropy path, reproducible firmware, and vendor transparency about exactly which builds are affected. Self-custody remains the right posture for many holders. Blind trust in any single firmware build is the part that has to change.
Coinkite's Response and Recall Status
Several details that owners will reasonably want are not yet independently confirmed, and I'm not going to paper over the gaps. As of this writing, The CyberSignal has not verified the specific affected firmware version, nor whether Coinkite has published a formal advisory or issued a firmware recall. It's also unconfirmed how many affected units remain in the field, whether the flaw touches specific model lines or the whole range, whether exchanges are blacklisting the stolen funds, and whether the FBI or Canada's RCMP are involved.
Those are exactly the questions a vendor advisory should answer, and they're the reason the checklist above leans on your own firmware version rather than on any assumption about which models are in scope. If Coinkite publishes an affected-version list and remediation guidance, that becomes the authoritative source — check it directly and follow its specifics over any general advice.
Open Questions
A few things will shape how big this gets. How many wallets generated seeds during the affected window, and how much of that value is still sitting on exposed addresses waiting to be swept? Whether the attacker has exhausted the predictable-seed population or is working through it in stages. Whether Coinkite's disclosure names precise firmware builds and model lines, so owners can move from “possibly affected” to a clear yes or no. And whether any of the 1,082.65 BTC can be frozen or traced through exchanges before it's laundered.
For now, the actionable part is narrow and clear. Check the firmware your seed was born on. If it falls in the affected window, generate a new seed on firmware that uses the hardware random source, and move your coins. This is a story about the quiet layer underneath the wallet — and about how long a single wrong number can wait before it costs someone $70 million.
Primary Documents
- The Hacker News — “Coldcard Hardware Wallet Flaw Linked to $70 Million Bitcoin Theft in 41 Minutes” (reporting the theft and Galaxy Research's root-cause finding)