Hardware wallet maker Coinkite is facing the fallout from what is shaping up to be the largest hardware wallet breach on record, after a vulnerability in Coldcard firmware allowed attackers to drain more than 1,778 Bitcoin, worth roughly $112M at prevailing prices, from over 5,000 addresses.
The theft began on July 30, 2026. Within 41 minutes, attackers had swept more than 1,000 BTC from over 1,000 addresses. As of mid-August 2026, approximately 1,531 BTC remained sitting untouched in wallets controlled by the attackers.
A bug that was hiding in plain sight since 2021
The root cause traces back to a firmware update Coinkite shipped in March 2021, version 4.0.1. That update introduced a flaw in the seed phrase generation process, the step where a hardware wallet creates the master key that controls all funds stored on it.
Instead of pulling randomness from the device’s dedicated hardware random number generator, the flawed code rerouted that process to a software-based pseudorandom number generator. The difference matters enormously: a software PRNG is far more predictable than its hardware counterpart, and predictable randomness in cryptography is essentially an open door.
A developer flagged a related issue to Coinkite as early as May 2025, according to research from Galaxy Research. The vulnerability apparently went unpatched long enough for attackers to develop and deploy tooling that exploited it at scale, hitting multiple Coldcard models including Mk2, Mk3, Mk4, Q, and Mk5.
Galaxy Research confirmed that at least a dozen distinct attackers were involved, all exploiting the same underlying weakness.
Coinkite’s response and what users need to do
Coinkite issued a security advisory on July 30, the same day the attacks started. By July 31, patched firmware was available for affected models. CEO Rodolfo Novak offered a public apology for the breach.
The critical detail for anyone who owns a Coldcard: a firmware update alone is not enough. Because the flaw corrupted seed generation at the point of wallet creation, any seed phrase generated on a vulnerable firmware version is compromised regardless of what firmware the device runs now. Coinkite’s guidance requires affected users to generate entirely new seed phrases on patched firmware and move all funds to the new wallets immediately.
What this means for the self-custody debate
The crypto industry has spent years making the case that self-custody is safer than trusting a centralized exchange. But the Coldcard breach complicates that narrative in a specific way: when a hardware wallet is hacked at the firmware level, the user is the last line of defense, and they often do not know there is a problem until the funds are gone.
A bug introduced in 2021, flagged in 2025, and weaponized in 2026 is not a comfortable timeline for an industry that markets hardware wallets as the gold standard of security. The question competitors will face from consumers and security researchers alike is straightforward: how do you verify that your RNG implementation is actually using hardware entropy, and how quickly can you push a verified patch when it is not.
Disclosure: This article was edited by Editorial Team. For more information on how we create and review content, see our Editorial Policy.

1 hour ago
13









English (US) ·