A firmware bug that Coinkite shipped in 2021 let attackers drain more than 1,778 Bitcoin, worth roughly $112 million, from over 5,000 Coldcard addresses in July 2026. The flaw corrupted seed-phrase generation, meaning affected users must create entirely new wallets rather than simply update firmware.
Hardware wallet maker Coinkite is facing the fallout from what is shaping up to be the largest hardware wallet breach on record, after a vulnerability in its Coldcard firmware let attackers drain more than 1,778 Bitcoin from over 5,000 addresses. The theft began on July 30, 2026, and within 41 minutes attackers had swept more than 1,000 BTC from over 1,000 addresses. As of mid-August 2026, approximately 1,531 BTC remained untouched in wallets controlled by the attackers.
A flaw hiding since 2021
The root cause traces back to a firmware update Coinkite shipped in March 2021, version 4.0.1. That update introduced a flaw in the seed-phrase generation process, the step where a hardware wallet creates the master key controlling all funds stored on it. Instead of pulling randomness from the device's dedicated hardware random number generator, the flawed code rerouted that process to a software-based pseudorandom number generator, which is far more predictable than its hardware counterpart.
A developer flagged a related issue to Coinkite as early as May 2025, according to research from Galaxy Research. The vulnerability went unpatched long enough for attackers to develop tooling that exploited it at scale, hitting multiple Coldcard models including the Mk2, Mk3, Mk4, Q, and Mk5. Galaxy Research also confirmed that at least a dozen distinct attackers were involved, all exploiting the same underlying weakness.
Coinkite's response and what users must do
Coinkite issued a security advisory on July 30, the same day the attacks started, and patched firmware was available for affected models by July 31. CEO Rodolfo Novak offered a public apology for the breach.
However, a firmware update alone does not fix the problem. Because the flaw corrupted seed generation at the point of wallet creation, any seed phrase generated on a vulnerable firmware version stays compromised regardless of what firmware the device runs now. Coinkite's guidance requires affected users to generate entirely new seed phrases on patched firmware and move all funds to the new wallets immediately.
A test for the self-custody narrative
The crypto industry has spent years arguing that self-custody is safer than trusting a centralized exchange. The Coldcard breach complicates that case: when a hardware wallet fails at the firmware level, the user is the last line of defense and often does not know there is a problem until the funds are gone. A bug introduced in 2021, flagged in 2025, and weaponized in 2026 leaves hardware wallet makers facing a pointed question from security researchers — how quickly they can verify and patch RNG implementations.
Source: Crypto Briefing
Trading involves risk.