A sophisticated attack drained over 1,000 BTC (worth ~$70 million) from 1,196 Coldcard hardware wallets in just 41 minutes on July 30, 2026. The theft didn't involve physical access or malware – instead, attackers exploited a critical firmware flaw that allowed them to reconstruct private keys offline.
The Vulnerability: Weak Seed Generation
Coldcard wallets are designed to generate seed phrases using a dedicated hardware randomness generator. However, an internal build setting skipped this generator, and a supporting library only checked if the setting existed, not if it was enabled. This caused key generation to fall back to a basic software substitute seeded from the chip's serial number and clock registers.
This reduced the possible key space from astronomically large to a computationally enumerable range. For Mk4, Q, and Mk5 models, attackers could brute-force through roughly 4 billion possibilities – a trivial task for modern computers.
The Attack: Systematic Enumeration
The attacker generated candidate seeds on their own hardware, derived addresses, and checked them against the public blockchain. This process ran entirely on the attacker's machine, meaning victims' devices were never involved and could be powered off in safes.
Galaxy Research's analysis revealed the attack swept funds across three address formats (native segwit, older standards), indicating a systematic scanner rather than targeted theft. The funds now sit in four addresses and remain unmoved.
The Aftermath: Uncertainty and Ongoing Risk
Coinkite (Coldcard's maker) initially warned Mk3 owners, but Block's report also implicates Mk2, Mk4, Q, and Mk5. Owners cannot easily determine if their seeds were generated on vulnerable firmware, leaving many in limbo.
Investigators found a crucial mistake: the attacker used a paid account at a blockchain data provider, whose logs matched the suspicious queries with "extraordinary specificity." This information has been passed to authorities.
The Bigger Picture: Cold Storage Isn't Bulletproof
This incident challenges the core promise of hardware wallets – that keys are unguessable. As computational power grows, even supposedly secure devices can be compromised without physical access. The attack underscores the need for rigorous firmware auditing and post-quantum cryptography to future-proof digital assets.
For now, affected users are urged to move their funds to wallets with freshly generated seeds, as further waves of attacks are likely.





Comments
Join Our Community
Sign up to share your thoughts, engage with others, and become part of our growing community.
No comments yet
Be the first to share your thoughts and start the conversation!