Geo News
Community curated by people like you
LatestAICryptoHealthWorld AffairsUS Politics
Coldcard hardware wallet flaw drains 594 BTC in 25-minute sweep
00

Coldcard hardware wallet flaw drains 594 BTC in 25-minute sweep

Jul 31, 2026

An attacker exploited a critical firmware vulnerability in Coldcard hardware wallets to steal 594 BTC (worth ~$38 million) from about 500 wallets in under 30 minutes. The flaw, introduced in March 2021, caused devices to use predictable, software-based key generation instead of a secure hardware randomizer. Coinkite, the wallet's manufacturer, and Block have warned users of affected models, particularly the Mk3, to move their funds immediately.

Coldcard wallet attack

  • ▪After the initial sweep, 562 BTC of the stolen funds were consolidated into a single address
  • ▪An attacker stole approximately 594 bitcoin, worth about $38 million, from around 500 single-signature wallets
  • ▪Block's security team began investigating after receiving reports of Bitcoin being remotely stolen from non-Bitkey wallets
  • ▪The theft of 594 BTC occurred between 01:31 and 01:56 UTC on July 31, 2026, affecting the wallets in under 30 minutes
  • ▪Security researchers identified an additional 695 transactions with the same on-chain fingerprint, potentially raising the total stolen amount to 1,082.59 BTC

Firmware vulnerability details

  • ▪The vulnerability caused affected Coldcard devices to skip their hardware randomness generator and use predictable, software-based key generation
  • ▪Importing a compromised seed into a new wallet does not eliminate the threat, as the seed itself remains vulnerable
  • ▪The flawed software-based key generation was seeded with non-secret data, including the chip's serial number and clock registers
  • ▪A build setting instructed the device to skip the hardware randomness generator, and a library check only verified the setting's existence, not its state

Affected device models

  • ▪A wallet's vulnerability depends on the firmware version running when its seed was created, not when the hardware was purchased
  • ▪Coinkite, the manufacturer, issued a warning specifically for users of its Coldcard Mk3 signing device
  • ▪Coinkite's early analysis stated that Mk4, Q, and Mk5 devices were not affected by the vulnerability that led to the theft
  • ▪Block engineer Max Guise recommended that anyone affected by the vulnerability move their funds as soon as possible
  • ▪Block's investigation identified security flaws in multiple generations of Coldcard wallets, including the Mk2, Mk3, Mk4, Q, and Mk5

Vulnerable firmware versions

  • ▪The vulnerability in the Coldcard Mk3 model extends through firmware version 5.0.3, the final version to support the device
  • ▪Coinkite warned that seeds created on an Mk3 device running firmware version 4.0.1 or any later Mk3 version may be at risk
  • ▪The vulnerability was introduced in Coldcard firmware version 4.0.0, which was shipped in March 2021

Compromised cryptographic functions

  • ▪For Coldcard Mk2 and Mk3 firmware, a coding error caused wallet generation to rely on predictable values instead of hardware-generated randomness
  • ▪In addition to wallet seeds, the flawed generator also produced private keys for paper wallets, seed-splitting masks, and device cloning keys
  • ▪Wallets protected with weak 25th-word passphrases and some multisignature setups could also be at risk from the vulnerability

4 sources

The Block
‘Funds may be at risk’: Coinkite issues warning for Coldcard Mk3 users amid 594 BTC theft reports
View source article
Cointelegraph
Coldcard Mk3 Warning Amid Unexplained 594 BTC Sweep
View source article
Coindesk
Major bitcoin wallet flaw drains 594 BTC in 25-minute sweep
View source article
U
Bitcoin Wallets at Risk After Critical Coldcard Security Bugs Get Exposed - U.Today
View source article

Story comments

Loading comments…

Related entities

Bitcoin

Topics

Coldcard MK5BitcoinBitcoin security & risksHardware wallet vulnerabilitiesBitcoin wallets & custodyCrypto hacks