Software Bug in Popular Bitcoin Hardware Wallet Allows Attackers to Drain 70 Million Dollars
New York, Saturday, 1 August 2026.
A five-year-old firmware error severely reduced security in Coldcard hardware wallets, allowing an attacker to drain over 70 million dollars in Bitcoin across 1,196 addresses in just 41 minutes.
Timeline and Scale of Exploitation
On July 30, 2026, a coordinated attack exploited a critical firmware vulnerability to drain 1,082.65 BTC from 1,196 addresses within a 41-minute window [1][2]. Galaxy Research confirmed the theft occurred between 01:10:20 and 01:51:26 UTC, valuing the lost assets at approximately $70.2 million USD at the time of the incident [2][5]. The average loss per compromised address amounts to roughly 58695.652 USD, highlighting the severity of the breach across the user base [2][5]. Blockchain analysts noted that the attacker consolidated the funds into a few large addresses, including one holding 562.02 BTC, which have remained inactive since the sweep [5][6]. This event marks one of the largest single hardware wallet compromises in cryptocurrency history, surpassing previous incidents in both speed and scale [1][4].
Technical Root Cause and Firmware History
The vulnerability originated from a firmware integration error introduced in March 2021, affecting Coldcard Mk3 devices running version 4.0.1 or later [2][3]. A configuration fault in the libngu cryptographic library caused the system to default to a predictable software-based pseudorandom number generator (PRNG) known as Yasmarang instead of the intended hardware random number generator (TRNG) [1][3]. This error significantly reduced entropy estimates to approximately 40 bits for Mk3 models, failing to meet the 128-bit security standard required for secure BIP-39 seed generation [1][4]. While the Mk3 was the primary target, Block engineering analysis indicated that Mk4, Mk5, and Q models possessed a “fail-open structure” that could also result in low-entropy seeds under specific boot exceptions [3][4]. The flaw remained undetected for over five years until the exploit pattern was identified by security engineers in late July 2026 [3][6].
Company Response and Mitigation Steps
Coinkite, the manufacturer behind Coldcard, issued an emergency firmware update on July 31, 2026, advising all users to generate new seeds and transfer funds to unaffected devices [1][2]. CEO Rodolfo Novak acknowledged full accountability for the firmware bug, stating that the company failed to catch the error during the review process [2][4]. Users who generated seeds using at least 50 independent dice rolls or employed a strong, unique BIP-39 passphrase not entered into a computer are considered at minimal risk [1][4]. However, security experts recommend that all users migrate assets to new seeds generated on patched or alternative hardware to ensure safety [4][6]. This incident follows the “Ill Bloom” vulnerability disclosed in early July 2026, underscoring ongoing challenges in hardware wallet security within the digital asset sector [1][4].