Back to News
Cybersecurity

Critical Firmware Vulnerability in Coldcard Wallet Leads to Major Bitcoin Heist

A firmware flaw in Coldcard hardware wallets has been linked to the theft of over $70 million in Bitcoin.

A significant security breach involving the Coldcard hardware wallet has revealed a critical firmware vulnerability that enabled an attacker to drain 1,196 Bitcoin addresses in just 41 minutes, resulting in a loss of 1,082.65 BTC valued at approximately $70.2 million on July 30. Galaxy Research has traced this incident back to a 2021 firmware integration error that improperly directed seed generation to a deterministic software pseudorandom number generator (PRNG), compromising the wallet's security framework.

For businesses utilizing Coldcard wallets or similar hardware solutions, this incident underscores the necessity of rigorous firmware updates and security audits to mitigate vulnerabilities that could lead to significant financial losses. Organizations should prioritize the implementation of multi-layered security protocols and consider regularly assessing their hardware wallet infrastructure to safeguard against such exploits. This breach not only emphasizes the ongoing risks associated with cryptocurrency storage solutions but also highlights the importance of robust cybersecurity practices within the rapidly evolving landscape of digital assets.

---

*Originally reported by [The Hacker News](https://thehackernews.com/2026/08/coldcard-hardware-wallet-flaw-linked-to.html)*