TheVortiq
Empresas

Coldcard Breach: $75M in Bitcoin Stolen Due to Seed Flaw

A firmware change in 2021 reduced the entropy of recovery seeds, allowing the theft of thousands of BTC.

August 3, 2026 · 4 min read

a wallet with bitcoins falling out of it

TL;DR: A vulnerability in Coldcard Mk3 wallets reduced the entropy of recovery seeds, allowing attackers to guess keys and steal over $75 million in Bitcoin. Users must generate new seeds immediately.

What Happened?

On August 2, 2026, a massive security breach was revealed affecting Coldcard hardware wallets, one of the most trusted devices by the Bitcoin community for securely storing cryptocurrencies. According to Slashdot, a code change in the firmware, implemented on March 1, 2021, caused Mk3 devices to silently fall back to a software-based pseudo-random number generator instead of the cryptographically secure hardware generator. This reduced the effective entropy of recovery seeds from 128 bits to approximately 40 bits, a search space small enough to be brute-forced with cloud computing resources.

Block's engineering team confirmed the finding, and Coinkite, the manufacturer of Coldcard, acknowledged it as preliminary but valid. Attackers exploited this weakness to calculate the seeds of a large number of wallets and transfer funds to addresses they controlled. According to Galaxy Research, by Saturday morning, approximately 1,158.66 BTC, valued at around $75.1 million, had been stolen from 2,673 addresses. Chainalysis, a blockchain analysis firm, observed that attackers prioritized wallets with the largest balances, extracting over $30 million in the first ten minutes of the attack.

Why It Matters

This incident is one of the largest Bitcoin thefts directly attributable to a vulnerability in hardware wallets, a type of device marketed as the most secure option for holding cryptocurrencies. The fundamental promise of a hardware wallet is that private keys never leave the device, and an attacker would need physical access to steal funds. However, the weakness in seed generation breaks that premise: anyone who can reproduce the seed can control the wallet without having the physical device.

The breach is particularly severe because it affects users who trusted Coldcard to store large amounts of Bitcoin. The loss of $75 million not only represents direct financial damage but also undermines trust in the security of hardware wallets in general. Moreover, this event highlights the fragility of firmware update processes: a seemingly minor change can introduce critical vulnerabilities that go unnoticed for years.

Consequences and Reactions

Coinkite has released a patched firmware, but warns that updating does not repair seeds already generated with the vulnerable version. Affected users must generate a new seed on an updated device and transfer their funds to the new wallet. This measure is urgent, as the exploit is considered active and ongoing. Galaxy Research has urged all Coldcard users with single-signature wallets to move their funds immediately.

The security community and authorities are already involved. Around 600 addresses believed to belong to the hackers have been reported to federal agencies, compliance firms, and cyber investigators. The scale of the attack has led to comparisons with other historical crypto heists, such as the Mt. Gox hack in 2014 or the Coincheck attack in 2018, though this case is unique because it exploits a hardware vulnerability rather than a centralized exchange.

For businesses and users, the consequences are multiple. First, the need to rigorously audit key generation processes in any security device. Second, the importance of keeping firmware updated and verifying the integrity of updates. Third, the urgency for hardware wallet manufacturers to implement entropy verification mechanisms and independent randomness tests.

What Readers Should Know

  • If you are a Coldcard user: check your model and firmware version. If you have an Mk3 device and generated a seed after March 1, 2021, assume your seed is potentially vulnerable. Generate a new seed on an updated device and transfer your funds as soon as possible.
  • Don't just update: updating the firmware does not fix existing seeds. You must create a new wallet from scratch.
  • Monitor your addresses: if you have already been a victim, funds have likely already been moved. Contact authorities and analytics platforms like Chainalysis to report the incident.
  • Consider diversification: for large holdings, consider using multiple devices from different manufacturers and custodians, as well as multi-signature wallets.
  • Demand transparency: the community must pressure manufacturers to publish independent security audits and demonstrate the quality of their random number generators.

This incident underscores that cryptocurrency security is not static: it requires constant vigilance, timely updates, and a deep understanding of emerging threats. The Coldcard breach is a reminder that even the most trusted devices can have critical flaws, and that the ultimate responsibility for custody lies with the user.

“The difference between 128 bits and 40 bits is not a matter of degree. It's the difference between a lock that cannot be forced and one that anyone can open with enough computing power.” — Analysis by TheVortiq

Stay informed and act with caution. The security of your digital assets depends on informed decisions and the adoption of best practices in an ever-evolving ecosystem.

Keep reading