Skip to content
Bitcoin

Coldcard Firmware Bug Drains 594 BTC in 25 Minutes, $38 Million Stolen

Bitcoin token standing among stacks of metallic coins.

An attacker exploited a critical flaw in Coldcard hardware wallets to sweep 594 bitcoin, worth approximately $38 million, from around 500 wallets in just 25 minutes. The theft, detailed in a report from CoinDesk, occurred early on July 31, 2026 (UTC) across 500 single-signature wallets, each holding more than 0.15 BTC, many dormant since 2021.

How the Vulnerability Undermined Key Generation

The bug was introduced in Coldcard Mk3 firmware version 4.0.0 released in March 2021. It caused devices to skip their hardware random-number generator and instead rely on a predictable software-based routine seeded with non‑secret chip identifiers. This made wallet seed phrases—normally considered unguessable—recoverable by an adversary. The weakness parallels high‑stakes Bitcoin vulnerabilities seen in past exploits such as the Balance Stablecoin Collapses 99% Following Bitcoin Price Oracle Exploit, where a pricing oracle failure caused catastrophic losses.

Within a single three‑block window, the attacker broadcast 1,324 chunks of bitcoin in 500 transactions and subsequently consolidated 562 BTC into one address that remains unmoved. Coinkite, the manufacturer, warned users who generated seeds on Mk3 devices running firmware 4.0.1 or later; Mk4, Q, and Mk5 models appear unaffected.

Market Reaction and User Safety Implications

Despite the severity of the loss, the incident had little visible impact on bitcoin’s market price, which has already weathered larger-scale supply overhangs—demonstrating the asset’s resilience in environments like the one discussed in our coverage of how Bitcoin Settles Near $65,000 as Oil’s March Toward $100 Fails to Spook the Market. The theft underscores the importance of using modern, multi‑factor key generation and highlights ongoing industry efforts to harden bitcoin’s security, such as the initiative by BlackRock, Coinbase, Strategy in a new group pledging $15 million to prepare Bitcoin for quantum threats.

Users with Coldcard Mk3 devices who created seeds during the affected firmware window are urged to move any remaining funds immediately. The exploit’s silent nature—targeting long‑dormant wallets—serves as a reminder that even cold storage requires diligent firmware updates and seed‑generation hygiene.

BTC-Pulse

Related stories

More coverage from this topic.