A critical firmware vulnerability in Coinkite's Coldcard Mk3 hardware wallets has resulted in over $115 million in stolen Bitcoin, affecting 8,680 addresses since July 30, 2026. The flaw, which went undetected for five years, caused the devices to generate weak cryptographic keys using serial numbers and internal clocks instead of a hardware random number generator. Galaxy Research reports that Wave 1 alone drained $70.2 million in under an hour, with some trackers estimating total losses could exceed $130 million.
Story comments
Loading comments…