BTC $71,807
2026 Bull Run Is Building Start trading with 5% OFF all fees
Sign Up Now
BTC $71,807
Bull Run 2026 | 5% Off Fees Open your Binance account today
Sign Up

15 Hackers Drain $130M+ from Coldcard Wallets

Firmware flaw lets 15 attackers steal $130M from Coldcard wallets.

  • At least 15 attackers have drained over $130 million from 7,300+ Coldcard wallets exploiting a firmware flaw that generated weak private keys, Galaxy Research reports.
  • The vulnerability, caused by a pseudo-random number generator in MicroPython, reduced seed entropy to roughly 40 bits on Mk2 and Mk3 models, making brute-force attacks feasible.
  • Coinkite has shipped hotfixes but warns that updating firmware does not repair seeds already generated, and “the threat is still active.”

Over 15 separate attackers have drained more than $130 million from at least 7,300 Coldcard hardware wallets, Galaxy Research concluded Tuesday, as exploitation of a newly discovered firmware flaw continues. The number of thieves appears to be growing daily, with Galaxy identifying a 15th attacker overnight after a victim reported losing less than one BTC.

- Advertisement -

The vulnerability stems from Coldcard’s firmware routing seed generation into MicroPython’s software fallback, a pseudo-random number generator instead of a true random generator. Coinkite, the manufacturer, estimates that Mk2 and Mk3 models produced seeds with only about 40 bits of entropy, far below the 128-bit target.

Consequently, any Hacker with sufficient knowledge and computational power can scan Bitcoin’s blockchain for vulnerable wallets and brute-force guess the private keys. Galaxy Research has heard from 73 victims as of Monday, and many long-term holders may not yet realize their losses.

Coinkite co-founder Rodolfo Novak wrote on July 31, “We take full accountability for the firmware bug and we offer our sincere apologies to those affected.” The company has since shipped hotfixes for every affected model but warned again today, “The threat is still active.”

Affected owners must move their BTC to new wallets, as updating the firmware does not repair a seed generated by flawed firmware. Interestingly, Galaxy reports that 90% of stolen coins have not moved, and none of the coins from the first three attack waves have been spent.

- Advertisement -

✅ Follow BITNEWSBOT on Telegram, Facebook, LinkedIn, X.com, and Google News for instant updates.

Previous Articles:

- Advertisement -
Ad
Altseason Is Loading. Don't watch from the sidelines.
SOL $90.51
DOGE $0.0963
LINK $9.02
SUI $1.00
5% off fees when you sign up
Start Trading
Ad
Pay Less on Every Trade. For Life.
$10K/mo volume Save $60/yr
$50K/mo volume Save $300/yr
$100K/mo volume Save $600/yr
5% off all trading fees when you sign up
Claim Your Discount

Latest News

BNB Smart Chain activates Pasteur hard fork to boost security and throughput

BNB Smart Chain activated the Pasteur hard fork on Tuesday, closing bridge verification and...

Space stocks fall 3% on Trump’s 1,000-launch memo

Space stocks SPCX and ASTS fell 3% after President Trump signed a memo targeting...

Strive Buys 1,110 Bitcoin, Issues Shares to Fund Treasury

Strive purchased 1,110 Bitcoin at an average price of $73,409.The company issued 3.65 million...

ZachXBT alleges BitcoinIRA, iTrustCapital hid data breaches

On-chain investigator ZachXBT alleged that BitcoinIRA and iTrustCapital suffered data breaches in 2026 without...

Bitcoin Hits $80,000; Sustained Strength Test Ahead

Bitcoin crossed $80,000 for the first time since mid‑May after Monday’s Wall Street open,...

Must Read

How to Buy Dedicated Hosting With Crypto

In this article I am going to show you how to buy dedicated hosting with crypto from one of the best European hosting providers...
Ad
Altseason Is Loading. These 4 coins are trending right now.
SOL $92.12
DOGE $0.0950
LINK $9.02
SUI $1.02
5% off spot fees when you sign up
Start Trading