Logo
My Crypto News AI

A $130 Million Firmware Bug Exposed Bitcoin's Biggest Self-Custody Weakness

A firmware bug in Coldcard hardware wallets weakened the randomness behind seed generation, exposing roughly $130 million in Bitcoin to attackers between late July and early August 2026. The flaw, which shipped since March 2021, reduced the effective entropy on some devices from 128 bits to as low as 40 bits, making private keys vulnerable to brute-force attacks once researchers reverse-engineered the vulnerability.

What Happened to Coldcard Wallets?

On July 30, 2026, attackers began systematically draining Coldcard wallets. Galaxy Research documented a single coordinated sweep that pulled approximately $70 million from 1,196 addresses in just 41 minutes. By August 4, TechCrunch reported the running total had climbed above $130 million, with at least a dozen different attackers exploiting the same vulnerability.

The root cause was not a stolen private key or phishing attack. Instead, Coinkite, the Canadian company behind Coldcard, had quietly changed how the device generated seeds. Rather than relying purely on the hardware random number generator, the flawed firmware hashed the device-generated seed together with every dice roll entered by the user. This seemingly minor change catastrophically weakened the cryptographic randomness, unless users had manually entered at least 50 independent dice rolls.

The timeline of losses accelerated as more researchers and attackers identified the vulnerability. On August 1, Coinkite shipped patched firmware. By August 3, reported theft had climbed to roughly 1,359 to 1,367 Bitcoin across approximately 4,585 addresses, totaling around $89 million. The losses continued climbing as attackers worked through exposed addresses over the following days.

Which Coldcard Models Were Affected?

Coinkite confirmed the bug affects multiple hardware wallet models and firmware versions. The impact varied by device generation. Mk2 and Mk3 units running firmware 4.0.1 through 4.1.9 saw entropy drop to roughly 40 bits without 50 or more manual dice rolls. Mk4, Mk5, and Q models on firmware released before mid-2026 patches experienced entropy reduction to approximately 72 bits instead of the intended 128 bits.

The company's other products, including TAPSIGNER, OPENDIME, and SATSCARD, run on separate codebases and were never at risk from this specific bug. However, updating firmware alone does not repair a seed that was already generated under the vulnerable code. Existing exposed seeds must be replaced and their funds migrated to new addresses.

How to Verify Your Hardware Wallet and Protect Your Funds

  • Check Your Device Model: Determine your exact Coldcard model by looking at the label on the back of the unit or the model name shown on the boot screen. Models include Mk2, Mk3, Mk4, Mk5, and Q, each with different bootloaders and firmware targets.
  • Read the Firmware Version from the Device: On Coldcard, navigate to Advanced/Tools, then Danger Zone, then Firmware Version. Never rely on the box or marketing materials. Cross-reference the version against Coinkite's official security advisory to determine if your device is affected.
  • Download Patched Firmware from Official Sources Only: Obtain the latest firmware exclusively from your vendor's official website or GitHub releases page. Mk2 and Mk3 units need firmware 4.2.0 or later; Mk4, Mk5, and Q models require their respective mid-2026 patches or newer.
  • Generate a New Seed with Manual Entropy: Use at least two physical dice to add randomness during seed generation. For Coldcard Mk2 and Mk3, enter at least 50 independent dice rolls to ensure adequate entropy. This step is critical because updating firmware does not fix seeds already generated under the vulnerable code.
  • Migrate Funds to the New Seed: Transfer all cryptocurrency from addresses derived from the old seed to addresses generated from your new, properly randomized seed. Test the new setup with a small amount of funds you can afford to lose before moving larger amounts.
  • Secure Your Backup Medium: Store your new seed on a steel or paper backup medium, not just the cardstock insert that ships with the device. Keep this backup in a secure location separate from your hardware wallet.

Why This Matters Beyond Coldcard

The Coldcard incident represents a fundamental challenge in hardware wallet security. For years, the pitch for hardware wallets was straightforward: keep your keys offline, and nobody can touch them remotely. The vulnerability complicates that narrative without entirely breaking it. The attack succeeded not because the device was connected to the internet, but because the cryptographic foundation itself was weakened.

This is distinct from previous hardware wallet security failures. Ledger's 2020 e-commerce database leak exposed customer contact information, not device keys, but it triggered years of phishing attempts against known Ledger buyers. The Coldcard flaw lives inside the cryptography itself, not around it. That distinction matters for how seriously users should treat firmware updates going forward.

TRM Labs called the Coldcard exploit the "largest hardware wallet exploit of 2026," and the damage kept climbing for days after disclosure. That wasn't because the attack kept evolving; it was because researchers kept finding more exposed addresses tied to the same root cause. The incident underscores that hardware wallet security now means more than just keeping the device unplugged from the internet. It requires vigilance about firmware versions, seed generation practices, and ongoing verification of device integrity.

For anyone holding cryptocurrency in self-custody, the Coldcard incident serves as a reminder that security is a continuous process. Checking your device model and firmware version, understanding how your seed was generated, and staying informed about vendor security advisories are no longer optional steps. They are essential practices for protecting digital assets in an environment where vulnerabilities can expose millions of dollars in minutes.