← BACK TO FEED
TAG

bitcoin security1 article

Coldcard's Firmware Bug Let an Attacker Drain $70 Million in Bitcoin in Under an Hour

A firmware bug in Coldcard hardware wallets, introduced in March 2021, routed seed generation to a weak software pseudorandom number generator instead of the device's hardware RNG, resulting in significantly reduced entropy and predictable wallet seeds. On July 30, an attacker exploited this vulnerability to drain 1,082.65 BTC (~$70.2 million) from 1,196 addresses in just 41 minutes. Coinkite released emergency firmware on July 31, but existing seeds remain compromised, and affected users must generate a new seed on patched firmware and transfer their funds.

2 Aug 2026