Coldcard Wallet Flaw Tied to $88.6M Bitcoin Theft
The theft happened 30 hours before Coinkite disclosed the vulnerability, and the scale of the loss points to automated attacks against wallets generated by a faulty RNG.
Reporting from 1 source: GIGAZINE.
Galaxy Research says a vulnerability in COLDCARD hardware wallet firmware was exploited in three attack waves after July 30, 2026, stealing about $88.6 million in Bitcoin. The attacks hit thousands of wallets whose seeds came from a defective random number generator. Coinkite stopped shipping COLDCARD and destroyed inventory.
Galaxy Research attributes the theft to a defective random number generator in COLDCARD firmware versions v4.0.0 through v5.0.3, released since March 2021. The attacks used a hardcoded fee rate of 30 satoshis per virtual byte and no change outputs, which the firm says indicates automated tools.
Coinkite, the Canadian manufacturer, said it stopped shipping COLDCARD immediately after confirming the flaw and destroyed all inventory. Other Coinkite products use a different codebase and are not affected, the company reported.
Synthesized by Yomimono from the 1 cited source below, including Japanese-language reporting where cited, then editorially reviewed before publishing.