Coldcard Vulnerability Drains 1,196 Bitcoin Addresses, Stealing $70.2 Million
ID: 69a505e0-9c9f-5a7c-8a6d-33b92b731bb2
STIX ID: report--69a505e0-9c9f-5a7c-8a6d-33b92b731bb2
Feed Name: Cyber Press
Threat Score
A firmware bug in Coldcard hardware wallets (introduced in a March 2021 update) routed seed generation through a software PRNG instead of the STM32 hardware RNG, reducing effective entropy to ~40–72 bits. On July 30, 2026, attackers exploited affected seeds to sweep 1,196 addresses and steal 1,082.65 BTC (~$70.2M) in a coordinated 41-minute operation; the vendor has released emergency patches and warned all users who generated seeds on vulnerable firmware to migrate funds immediately.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
