Major bitcoin wallet flaw drains 594 BTC in 25-minute sweep
Reported by CoinDesk · AI-assisted summary by ChikoCorp AI News Desk

AI-assisted summary based on the linked source. Verify market-moving details at the original publisher before acting.
On July 31, 2026, it was reported that an attacker exploited a key generation flaw in certain Coldcard hardware wallets to steal approximately 594 bitcoin, valued at about $38 million. The theft affected around 500 single-signature wallets and took place over a fast 25-minute window between 01:31 and 01:56 UTC. The stolen coins were moved in over 500 transactions within a three-block span, with much of the bitcoin consolidated into a single address that has not moved since. Many of the compromised wallets had been inactive for years, and the coins involved dated from 2021 to 2026, aligning closely with the timeframe of the flaw's introduction.
The vulnerability was rooted in firmware version 4.0.0 released by Coldcard in March 2021. Instead of using hardware-generated randomness to create wallet keys, the devices fell back to a predictable software-based method seeded with nonsecret chip data such as the device's serial number and clock registers. These data points are well-known and easily obtainable, allowing attackers to reconstruct seeds and gain access to wallets. The flaw originated from a build setting that mistakenly skipped the hardware randomness generator, a detail confirmed in a report by Block's Bitcoin engineering and security teams. Coinkite, the Canadian company behind Coldcard wallets, confirmed their awareness of the issue following disclosure by Block.
Coinkite has issued warnings to users who generated seeds on Mk3 devices running firmware 4.0.1 or later, stressing that newer Coldcard models like Mk4, Q, and Mk5 appear unaffected based on early analyses. Importantly, exposure to the vulnerability depends not on the device's physical hardware generation but on the firmware version active when the wallet was initially created. The insecure key generation affected not only the wallet seeds but also private keys for Coldcard paper wallets, seed-splitting masks, cloning keys, and Key Teleport transfers. Despite the substantial theft, the incident has not noticeably impacted bitcoin’s market price, which remained above $64,000 in early Asian trading hours following the attack.