your 'safest' Bitcoin wallet had a broken lock since 2021 — and hackers just found it

A five-year-old firmware bug in Coldcard hardware wallets let attackers drain $116 million in Bitcoin this summer — and if you generated a seed on…

Aliteq
Sam Okafor · Web3 & Chains Editor

The short version

A Coldcard firmware bug from March 2021 (version 4.0.1) routed seed generation to a weak software random-number generator instead of the device's dedicated hardware chip.

The short version

Attackers began exploiting it July 30, 2026, draining roughly 1,816 BTC, about $116 million, from over 5,200 addresses across four separate waves.

The short version

Coinkite shipped patched firmware within 24 hours, but the fix only protects seeds generated after the update — anything made on vulnerable firmware between 2021 and 2026 should be treated as…

The short version

TRM Labs ranks it the third-largest crypto hack of 2026, in a year that's already lost over $1.2 billion across 276 incidents.

The short version

Coinkite is now facing a class-action threat and reversed its own privacy-first data-deletion policy to prepare for potential legal proceedings.

Only use Coinkite's own instructions

Everything in this section comes from Coinkite's security advisory (current guidance dated 14 August 2026) and the COLDCARD Security Status page (most recent changelog entry: 6 September 2026), both…

Aliteq

Read the full story

your 'safest' Bitcoin wallet had a broken lock since 2021 — and hackers just found it

Read the full story on Aliteq