Skip to content
FinaPedia logoFinaPedia
Security

Coldcard Wallet Vulnerability Leads to $114M Bitcoin Loss

By FinaPedia Editorialvia Bitcoin Magazine2 min read
Coldcard Wallet Vulnerability Leads to $114M Bitcoin Loss
The Brief

Hackers have exploited a critical vulnerability in Coldcard hardware wallets, resulting in the theft of an estimated $114 million in Bitcoin. The ongoing attacks, which intensified over the weekend, have seen significant amounts of the cryptocurrency drained from user wallets.

The issue stems from a firmware bug in Coldcard Mk3 devices, introduced in version 4.0.1 in March 2021. This flaw caused the seed generation process to revert to a less secure software pseudorandom number generator instead of the intended hardware-based true random number generator. This allowed malicious actors to effectively guess users' seed phrases and gain access to their funds.

Coinkite, the manufacturer of Coldcard, has acknowledged the vulnerability affects all its models. In response, the company has halted shipments of affected products and destroyed remaining inventory produced with the compromised firmware. They have also initiated an internal review, with engineers investigating the incident and reporting findings to federal authorities and a blockchain services provider used by the hackers to move funds. The company expressed deep regret over the financial losses and broken trust experienced by its customers.

By the numbers

Daily close, August 3, 2026 · Data: CoinGecko

BitcoinBTC
$63,504.42
$1.3T market cap$15.9B 24h volume
React
Share

This is an AI-assisted summary. Original reporting by Bitcoin Magazine.

Read the original

Related stories