Technology

Coldcard Cold Wallet Heist: $70M Stolen Without Touching Devices – Here's How

Coindesk2 min read119 views
Coldcard Cold Wallet Heist: $70M Stolen Without Touching Devices – Here's How

A sophisticated attack drained over 1,000 BTC (worth ~$70 million) from 1,196 Coldcard hardware wallets in just 41 minutes on July 30, 2026. The theft didn't involve physical access or malware – instead, attackers exploited a critical firmware flaw that allowed them to reconstruct private keys offline.

The Vulnerability: Weak Seed Generation

Coldcard wallets are designed to generate seed phrases using a dedicated hardware randomness generator. However, an internal build setting skipped this generator, and a supporting library only checked if the setting existed, not if it was enabled. This caused key generation to fall back to a basic software substitute seeded from the chip's serial number and clock registers.

This reduced the possible key space from astronomically large to a computationally enumerable range. For Mk4, Q, and Mk5 models, attackers could brute-force through roughly 4 billion possibilities – a trivial task for modern computers.

The Attack: Systematic Enumeration

The attacker generated candidate seeds on their own hardware, derived addresses, and checked them against the public blockchain. This process ran entirely on the attacker's machine, meaning victims' devices were never involved and could be powered off in safes.

Galaxy Research's analysis revealed the attack swept funds across three address formats (native segwit, older standards), indicating a systematic scanner rather than targeted theft. The funds now sit in four addresses and remain unmoved.

The Aftermath: Uncertainty and Ongoing Risk

Coinkite (Coldcard's maker) initially warned Mk3 owners, but Block's report also implicates Mk2, Mk4, Q, and Mk5. Owners cannot easily determine if their seeds were generated on vulnerable firmware, leaving many in limbo.

Investigators found a crucial mistake: the attacker used a paid account at a blockchain data provider, whose logs matched the suspicious queries with "extraordinary specificity." This information has been passed to authorities.

The Bigger Picture: Cold Storage Isn't Bulletproof

This incident challenges the core promise of hardware wallets – that keys are unguessable. As computational power grows, even supposedly secure devices can be compromised without physical access. The attack underscores the need for rigorous firmware auditing and post-quantum cryptography to future-proof digital assets.

For now, affected users are urged to move their funds to wallets with freshly generated seeds, as further waves of attacks are likely.

  • #coldcard
  • #bitcoin
  • #security
  • #hardwarewallet
  • #exploit

Comments Β· 0

Get the top stories by email

Join our newsletter and get the latest updates delivered straight to your inbox.

BT

BitcoinToday.app

Get BitcoinToday.app on your phone!