ALITEQ.

your 'safest' Bitcoin wallet had a broken lock since 2021 and hackers just found it

A five-year-old firmware bug in Coldcard hardware wallets let attackers drain $116 million in Bitcoin this summer — and if you generated a seed on one between 2021 and July 2026, your coins might still be exposed.

Sam OkaforUpdated 1h ago7 min readWeb story
A small hardware cryptocurrency wallet device used for offline Bitcoin storage

Coldcard built its reputation on being the hardware wallet security people trust with real money — air-gapped, open-source, Bitcoin-only. On July 30, 2026, attackers started proving that reputation had a five-year-old hole in it. A firmware bug shipped in March 2021 had been quietly weakening the random numbers Coldcard used to generate wallet seeds. By the time Coinkite, the company behind Coldcard, patched it, roughly 1,816 BTC, about $116 million, had been drained from more than 5,200 addresses.

How a hardware chip got skipped for five years

The bug itself is almost embarrassingly simple to explain, per The Hacker News' technical writeup. Coldcard devices are supposed to pull randomness for a new wallet seed from a dedicated hardware random-number generator built into the chip — the part of the security story that's supposed to make a hardware wallet meaningfully safer than software. A production configuration error in the March 2021 firmware build set a flag called MICROPY_HW_ENABLE_RNG to zero, which silently rerouted seed generation to MicroPython's software fallback generator instead. That dropped the effective entropy from the 128 bits a secure seed needs down to somewhere between 40 and 72 bits depending on the model, weak enough to brute-force without ever touching the physical device.

~1,816

BTC stolen

Roughly $116 million at time of theft

5,200+

Addresses hit

Across four separate waves

5 years

Bug lifespan

March 2021 to July 2026

$1.2B+

2026 crypto losses so far

Across 276 incidents, per TRM Labs

How the theft unfolded

  1. Mar 2021

    Coinkite ships firmware 4.0.1 with the RNG misconfiguration, unnoticed for five years.

  2. Jul 30, 2026

    First wave: about 594 BTC (~$38M) drained from roughly 500 addresses in 25 minutes.

  3. Jul 31, 2026

    Coinkite posts an emergency advisory and ships patched firmware for every model within a day.

  4. Aug 1–3, 2026

    Two more waves push the total to roughly 1,367 BTC (~$89M) from 4,585 addresses.

  5. Aug 7, 2026

    Coinkite reverses its data-deletion policy, citing anticipated legal obligations.

Coinkite's CEO, who goes by NVK, didn't soften the warning when the advisory went out: 'If you generated a seed using a Coldcard wallet, move your funds now, using our updated best practices, before reading further.' That's not boilerplate. Installing the new firmware only protects seeds generated after you update it. Anything created on a vulnerable Coldcard between March 2021 and the patch needs to be treated as burned, full stop, even if it's sitting untouched today.

A small USB-connected hardware wallet device used to store cryptocurrency offline
Hardware wallets are supposed to keep private keys away from any internet-connected device — this bug undermined that at the source. · Unsplash

Who actually got hit, and how they're being caught

Galaxy Research and TRM Labs have been running the on-chain math since the first wave, and the pattern is uglier than a single opportunistic hacker cashing in. Transaction construction differs across the four waves enough that researchers think multiple attackers may be working the same vulnerability independently. TRM traced part of the stolen funds through a 64.9 BTC deposit into Wasabi Wallet and roughly 200 ETH routed through Tornado Cash on August 4, standard mixing playbook, not a sign anyone's slowing down. Canadian holders took the largest share of the losses, around a quarter of the total, ahead of victims in the US and Thailand.

The part that should worry every hardware-wallet owner

This is where I'll push back on the instinct to treat this as a Coinkite-specific story. Coldcard passed years of scrutiny from a security-conscious community that reads firmware changelogs for fun, and the flaw still sat live for five years. It fits a pattern running through 2026's worst security stories — a ransomware gang running its command infrastructure on the Polygon blockchain, a single hijacked npm maintainer account turning into a billion-download supply-chain attack, 15 million dental patient records exposed, where the failure isn't a dramatic zero-day, it's one overlooked default that nobody rechecked for half a decade. Self-custody was supposed to remove counterparty risk. It just relocated the risk to a chip most owners never once thought to question.

The fallout is already reaching lawyers. Thomas Braziel of 117 Partners is examining product liability and class-action claims against Coinkite on behalf of affected holders, and legal experts are split on how strong that case actually is — a defect claim is plausible, but device makers have historically had wide latitude to disclaim this kind of loss in their terms of service. Coinkite's decision to stop automatically deleting customer records, a reversal of a policy the brand built its entire privacy pitch around, is itself the clearest signal that the company expects to end up in court.

Self-custody relocates risk rather than eliminating it.

TRM Labs

Is my Coldcard still vulnerable?
Only if you haven't updated. Mk2/Mk3 need firmware 4.2.0 or later, Mk4/Mk5 need 5.6.0 or later, and the Coldcard Q needs 1.5.0Q or later. Updating alone doesn't fix seeds already generated on old firmware — those need to be replaced.
How much was actually stolen?
Roughly 1,816 BTC, worth about $116 million at the time of the thefts, taken from more than 5,200 addresses across four waves between July 30 and early August 2026.
What caused the bug?
A March 2021 firmware build (version 4.0.1) mistakenly disabled the hardware random-number generator, routing seed creation through a much weaker software fallback instead.
Can I get my funds back?
Not through Coinkite directly for coins already stolen. Some victims are pursuing legal claims through firms like 117 Partners, but recovery isn't guaranteed and experts describe the legal case as genuinely uncertain.
Are other hardware wallets affected?
No reports have tied this specific bug to other manufacturers, it's a Coldcard/Coinkite firmware defect, not an industry-wide flaw. But it's a reminder that 'hardware wallet' isn't a synonym for 'unhackable' — the same lesson applies to enterprise gear that's supposed to be locked down too.

Watch two things from here. First, whether Coinkite ever publishes a real number instead of the range analysts have pieced together on-chain, reporting says the company still won't estimate its own losses. Second, whether the class-action threat turns into an actual filing, because that outcome will set the precedent for how liable a hardware-wallet maker can be held when the failure is in the chip, not the user. Until then, if you've ever owned a Coldcard, check your firmware version before you do anything else today.

Web3 & Chains Editor

Sam Okafor

Sam covers web3 the way a security researcher would — following the infrastructure and the incentives, not the moon-talk. He's far more interested in how a chain actually works (and where it breaks) than in what its token did this afternoon.

The Aliteq brief

The tech worth knowing — hardware, AI, gaming, deals. No spam, unsubscribe anytime.

Keep reading