Coldcard Firmware Bug Leads to $89 Million Bitcoin Theft
Coinkite is urging users to migrate funds after a firmware vulnerability in Coldcard wallets allowed attackers to steal approximately 1,367 BTC from over 4,500 addresses.
A pseudo-random number generator vulnerability in Coldcard hardware wallets has resulted in the theft of approximately 1,367 BTC, valued at roughly $89 million, across 4,585 addresses. The flaw originated from a March 2021 firmware release where a misconfigured preprocessor macro in the libngu library caused devices to use a software fallback instead of a hardware random-number generator. This reduced effective entropy from 128 bits to only 40 bits, making private keys predictable and allowing attackers to reconstruct them offline.
Coinkite issued a security notice on July 30, 2026, shortly before thefts began in three distinct waves. The first wave drained $70 million in just 41 minutes. Galaxy Research reported a potential fourth wave emerging on August 3 and has provided federal investigators with data on 600 suspected attacker-controlled addresses. The company released emergency hotfixes but warned that updating firmware cannot repair seeds already generated by the affected software.
CEO Rodolfo Novak apologized for the bug and stated the company is taking full accountability. In response to the exploit, Binance founder Changpeng Zhao cautioned users against blind faith in hardware wallets, while TRM Labs suggested the incident proves that self-custody does not eliminate risk. The event has triggered a surge in Bitcoin transfers as users migrate funds to exchanges or new wallets.