How bitcoin cold wallets lost $70 million in an attack that never touched the devices
Reported by CoinDesk · AI-assisted summary by ChikoCorp AI News Desk

AI-assisted summary based on the linked source. Verify market-moving details at the original publisher before acting.
On July 30, 2026, over 1,000 bitcoin worth approximately $70 million were stolen from 1,196 Coldcard hardware wallets in a rapid attack lasting 41 minutes. This amount nearly doubled the initially reported $35 million loss. Galaxy Research analyzed the event, noting that 1,082.65 BTC were moved across six blocks in the specified window, with transactions broadcast in batches rather than continuously. The stolen funds were consolidated into four addresses, which have not yet been moved. The attack is significant not just for the amount, but for the method used.
The theft exploited a firmware flaw in certain Coldcard models that reduced the range of possible seed phrases from an astronomical number to roughly four billion. Coldcard wallets are designed to generate a private key seed using a hardware random number generator; however, due to a build setting issue and insufficient library checks, the seed generation fell back to a software method seeded by the device’s fixed serial number and timing registers. This dramatically weakened security, allowing an attacker to systematically generate and test possible seeds offline until matching wallets were found. Because this damage occurred in seed generation, the attacker never needed physical access or to interact with the actual hardware wallets.
The vulnerability affects multiple Coldcard versions, including Mk2, Mk3, Mk4, Q, and Mk5 models. Coinkite has warned Mk3 users and stated newer models are not affected, but owners cannot reliably determine if their seed was generated on compromised firmware. This means more wallets are potentially exposed, and further thefts may occur unless users move their funds. The attack was systematic, targeting multiple address formats indicating enumeration rather than specific wallets.
Investigators identified clues that may help track the attacker. The perpetrator used a paid account at a well-known blockchain data provider to query source addresses during the theft, a behavior recorded in provider logs with high specificity regarding timing and request sequence. This information has been passed to authorities for further action. The incident highlights a shift in crypto security challenges, showing that safe storage involves safeguarding the unpredictability of keys themselves, as even some hardware wallets can be compromised through flaws in key generation processes.