your 'safest' Bitcoin wallet had a broken lock since 2021 — and hackers just found it

A five-year-old firmware bug in Coldcard hardware wallets let attackers drain $116 million in Bitcoin this summer — and if you generated a seed on…

Aliteq
Sam Okafor · Web3 & Chains Editor

The short version

A Coldcard firmware bug from March 2021 (version 4.0.1) routed seed generation to a weak software random-number generator instead of the device's dedicated hardware chip.

The short version

Attackers began exploiting it July 30, 2026, draining roughly 1,816 BTC, about $116 million, from over 5,200 addresses across four separate waves.

The short version

Coinkite shipped patched firmware within 24 hours, but the fix only protects seeds generated after the update — anything made on vulnerable firmware between 2021 and 2026 should be treated as…

The short version

TRM Labs ranks it the third-largest crypto hack of 2026, in a year that's already lost over $1.2 billion across 276 incidents.

The short version

Coinkite is now facing a class-action threat and reversed its own privacy-first data-deletion policy to prepare for potential legal proceedings.

If you own a Coldcard, do this now

Update to firmware 4.2.0+ on Mk2/Mk3, 5.6.0+ on Mk4/Mk5, or 1.5.0Q+ on the Q. Then generate a brand-new seed on the patched firmware — don't just keep using the old one. Move your coins to the new…

Aliteq

Read the full story

your 'safest' Bitcoin wallet had a broken lock since 2021 — and hackers just found it

Read the full story on Aliteq