• About Us
  • Advertise
AltcoinReporter
  • Home
  • News
    • Bitcoin
    • Ethereum
    • Blockchain
    • Altcoins
    • DeFi
    • NFT
  • Press Releases
  • Reviews
    • Exchanges
    • NFT Marketplaces
    • Wallets
  • Market Analysis
  • Contact Us
No Result
View All Result
  • Home
  • News
    • Bitcoin
    • Ethereum
    • Blockchain
    • Altcoins
    • DeFi
    • NFT
  • Press Releases
  • Reviews
    • Exchanges
    • NFT Marketplaces
    • Wallets
  • Market Analysis
  • Contact Us
No Result
View All Result
AltcoinReporter
No Result
View All Result
Home Bitcoin

The Coldcard Attack Drained $70 Million Without Touching a Single Device

Salar Salek by Salar Salek
August 2, 2026
in Bitcoin
The Coldcard Attack Drained $70 Million Without Touching a Single Device

The pitch for a hardware wallet is simple. Keep your private keys on a device that never touches the internet, and no attacker can reach them. Coldcard, made by Canadian firm Coinkite, is among the most respected products in that category, a Bitcoin-only, air-gapped device favoured by long-term holders who take custody seriously.

On July 30, roughly 1,200 of those wallets were emptied. None of the devices were touched.

Related articles

Strategy Booked an $8.2 Billion Loss and Sold Bitcoin for the First Time in Four Years

Strategy Booked an $8.2 Billion Loss and Sold Bitcoin for the First Time in Four Years

August 2, 2026
BlackRock, Coinbase and Strategy Are Funding Bitcoin’s Quantum Defense With $15 Million

BlackRock, Coinbase and Strategy Are Funding Bitcoin’s Quantum Defense With $15 Million

July 24, 2026

An attacker swept 1,082.65 bitcoin, worth about $70 million, from 1,196 addresses in a 41-minute window, according to Galaxy Research. The initial figure reported was roughly 594 BTC from around 500 wallets. It nearly doubled within a day as investigators traced more addresses, and reports suggest drains are still ongoing.

Cold storage does two jobs. It keeps your key somewhere no hacker can reach, and it creates a key no computer can guess. The first job held perfectly. Every drained wallet sat offline and untouched while its seed was reconstructed on someone else’s machine. The second job had been quietly broken for five years.

A Macro That Was Defined but Set to Zero

The root cause is a firmware integration error introduced in Coldcard version 4.0.0 in March 2021, documented by Block’s Bitcoin engineering team.

Coldcard’s firmware deliberately defined a build constant, MICROPY_HW_ENABLE_RNG, and set it to zero. The intent was to disable MicroPython’s built-in randomness path, because Coinkite had written its own dedicated wrapper for the device’s hardware random number generator. That was a reasonable design choice.

The problem sat in a supporting cryptographic library called libngu, which checked only whether the macro existed, not whether its value was non-zero. Because the macro was defined at all, even as zero, the build was bound to MicroPython’s software fallback generator instead of the hardware one.

That fallback was initialised from the chip’s unique ID and timer registers, and collected no fresh entropy afterwards. Both inputs are non-secret. As a result, seeds that should have carried 128 bits of entropy carried roughly 40 bits on the Mk3 and about 72 bits on the Mk4, Mk5 and Q, according to Coinkite’s own estimates. Forty bits reduces the possible seed values to roughly four billion, a range a determined attacker can enumerate offline.

From there the attack requires no device access at all. Reproduce the candidate output streams, derive the addresses each seed would generate, and compare them against the public blockchain. Any match is a funded wallet with a known key.

Who Is Affected

Coinkite initially flagged only Mk3 devices before expanding the warning across its range. Current guidance covers Mk3 on firmware 4.0.1 to 4.1.9, Mk4 and Mk5 below 5.6.0, and Coldcard Q below 1.5.0Q. Reports indicate the company now considers every current model affected to some degree.

One group escaped entirely. Coldcard lets users supplement device randomness with their own dice rolls during setup, and seeds generated with 50 or more dice rolls carried genuine entropy the attacker could not reproduce. Those wallets survived untouched, which is a striking vindication of a feature many owners skipped as excessive caution.

The exposure also extends past wallet seeds. The same generator produced Coldcard’s paper wallet private keys, where the output becomes the key directly, along with seed-splitting masks, device cloning keys and Key Teleport transfers.

Coinkite shipped emergency firmware for every affected model on July 31, including Mk3 version 4.2.0. But the critical point, which the company has stressed repeatedly, is that updating firmware does not repair an existing seed. Restoring a compromised seed onto patched firmware, or onto any other wallet, carries the weakness forward. The only remedy is generating a new seed on fixed firmware and migrating funds to it.

Jan3 chief executive Samson Mow put it bluntly on X: if you’re using a Coldcard, any firmware version or model, migrate your funds immediately.

The Mistake the Attacker Made

There is one thread investigators are pulling on, and it is a careless one.

Block’s Clay Garrett said the operator used a paid account at a well-known blockchain data provider to query the source addresses during the sweeps. The provider’s internal logs matched the suspected workflow with what Garrett described as extraordinary specificity, down to the number, timing and sequence of requests.

An attacker who spent months reconstructing seeds offline then queried them through a commercial account that logs everything. Whether that leads anywhere depends on what identifying information the provider holds, but it is the kind of operational error that has ended similar cases before.

One caveat worth stating plainly: no public report has yet reconstructed a specific victim’s seed and matched it to a drained address. The attribution rests on the firmware analysis, the blockchain pattern and Coinkite’s own acknowledgment, which is substantial but not the same as a demonstrated end-to-end reproduction. Both Block and Coinkite described their initial analyses as preliminary, with Block publishing before full testing because exploitation was already under way.

What This Changes

The uncomfortable lesson is that self-custody advice has been incomplete. The industry has spent a decade telling people to get their coins off exchanges and onto hardware wallets, and that advice remains sound. But it implicitly treated key generation as a solved problem, something the device handles correctly by definition.

It isn’t. The quality of randomness at the moment a seed is created is a distinct security property from where the key is stored afterwards, and it is far harder for a user to verify. An owner can confirm their device is air-gapped. Almost nobody can confirm the entropy behind their seed, which is precisely why security firms warn that more wallets may still be drained: affected owners cannot reliably determine whether they were exposed. They have to assume they were.

That points to two practical takeaways. First, user-supplied entropy is not paranoia. The dice-roll option that saved a subset of Coldcard holders exists on multiple hardware wallets and costs a few minutes at setup. Second, open-source firmware is necessary but not sufficient. Coldcard’s code was public for five years, and the bug survived because it lived in the interaction between a build configuration and a library’s assumption, exactly the kind of flaw casual review misses.

Bitcoin traded above $64,000 through the initial sweep with little visible market impact, and has since drifted toward $62,900 amid broader macro pressure rather than anything specific to this incident. The $70 million is painful for those affected and negligible against a $1.26 trillion asset.

The reputational damage is the more lasting cost. Coldcard was a device people trusted specifically because it did one thing carefully. That trust now needs rebuilding, and every hardware wallet manufacturer should be auditing their entropy path this week.

FAQ

What actually happened?
An attacker drained 1,082.65 bitcoin, roughly $70 million, from 1,196 addresses in a 41-minute window on July 30, 2026. The attack exploited a firmware integration error introduced in Coldcard version 4.0.0 in March 2021, which caused devices to use a predictable software random number generator instead of the hardware one. Seeds carried roughly 40 bits of entropy on the Mk3 and about 72 bits on newer models, rather than the 128-bit standard, allowing the attacker to reconstruct private keys offline without ever accessing a device.

Which devices are affected and what should owners do?
Coinkite’s guidance covers Mk3 on firmware 4.0.1 to 4.1.9, Mk4 and Mk5 below 5.6.0, and Coldcard Q below 1.5.0Q, with reports suggesting the firm now considers all current models affected to some degree. Seeds generated with 50 or more user dice rolls carried genuine entropy and were not vulnerable. Emergency firmware shipped July 31, but updating alone does not fix an existing seed. Affected owners must generate an entirely new seed on patched firmware and migrate their funds to it.

Does this mean hardware wallets are unsafe?
Not broadly, but it exposes a gap in how self-custody is usually explained. Air-gapping worked exactly as intended here; every drained wallet remained offline. The failure was in key generation, a separate security property that users cannot easily verify. The practical response is to use user-supplied entropy such as dice rolls where a device offers it, and to recognise that open-source firmware alone does not guarantee correctness, as this bug survived five years of public code review.

Disclaimer: This article is for informational purposes only and does not constitute financial or security advice. Cryptocurrency investments carry significant risk. Always conduct your own research before making any investment decisions.

Salar Salek

Salar Salek Verified AltcoinReporter Author

Salar covers cryptocurrency markets, blockchain technology, DeFi, and emerging digital asset trends for AltcoinReporter. With a background in technology and finance, he has been actively following and investing in the...

Read More
Tags: Bitcoin SecurityCoinkiteColdcardhardware walletSelf-Custody

Related Posts

Strategy Booked an $8.2 Billion Loss and Sold Bitcoin for the First Time in Four Years

Strategy Booked an $8.2 Billion Loss and Sold Bitcoin for the First Time in Four Years

by Salar Salek
August 2, 2026
0

A year ago, Strategy reported a $10.02 billion profit for the second quarter. The company was the definitive proof of...

BlackRock, Coinbase and Strategy Are Funding Bitcoin’s Quantum Defense With $15 Million

BlackRock, Coinbase and Strategy Are Funding Bitcoin’s Quantum Defense With $15 Million

by Salar Salek
July 24, 2026
0

Bitcoin's largest institutional backers spend most of their time competing. BlackRock and Fidelity chase the same ETF investors. Coinbase and...

Michael Saylor Just Published ‘110 Reasons’ to Kill a Bitcoin Cleanup Proposal

Michael Saylor Just Published ‘110 Reasons’ to Kill a Bitcoin Cleanup Proposal

by Salar Salek
July 20, 2026
0

Michael Saylor doesn't usually get involved in the technical weeds of Bitcoin protocol debates. As executive chairman of Strategy, the...

The US Government Just Moved $288 Million in Seized Crypto to Coinbase Prime

The US Government Just Moved $288 Million in Seized Crypto to Coinbase Prime

by Salar Salek
July 18, 2026
0

In a market already gripped by extreme fear, few things spook traders more than the possibility of a very large...

Strategy Just Sold Bitcoin Days After Buying It, Netting Only 69 Coins for $20 Million

Strategy Just Sold Bitcoin Days After Buying It, Netting Only 69 Coins for $20 Million

by Salar Salek
July 8, 2026
0

For nearly six years, Michael Saylor's message never wavered. "Never sell your Bitcoin," he told followers. "Sell a kidney if...

Load More
  • Trending
  • Comments
  • Latest
Solana Alpenglow Upgrade 2026: Launch Date, Features, and What It Means for SOL

Solana Alpenglow Upgrade 2026: Launch Date, Features, and What It Means for SOL

April 18, 2026
Dogecoin and Meme Coins

Dogecoin and Meme Coins Face a Reality Check as Speculative Demand Fades

June 14, 2026
Solana’s Alpenglow Upgrade: The Biggest Change to SOL Since Launch

Solana’s Alpenglow Upgrade: The Biggest Change to SOL Since Launch

April 7, 2026
Justin Sun vs WLFI: “See You in Court” as Backdoor Token Freeze Row Explodes

Justin Sun vs WLFI: “See You in Court” as Backdoor Token Freeze Row Explodes

April 13, 2026
North Korea’s Six-Month Con: How Hackers Stole $286M from Solana’s Drift Protocol

North Korea’s Six-Month Con: How Hackers Stole $286M from Solana’s Drift Protocol

0
Ethereum’s Glamsterdam Upgrade: What It Is and Why It Matters in 2026

Ethereum’s Glamsterdam Upgrade: What It Is and Why It Matters in 2026

0
Bitcoin’s Worst Q1 Since 2018: Can April Turn the Tide?

Bitcoin’s Worst Q1 Since 2018: Can April Turn the Tide?

0
Former UK Chancellor Kwarteng Leads Bitcoin Firm as Farage Backs BTC

Former UK Chancellor Kwarteng Leads Bitcoin Firm as Farage Backs BTC

0
Strategy Booked an $8.2 Billion Loss and Sold Bitcoin for the First Time in Four Years

Strategy Booked an $8.2 Billion Loss and Sold Bitcoin for the First Time in Four Years

August 2, 2026
The Coldcard Attack Drained $70 Million Without Touching a Single Device

The Coldcard Attack Drained $70 Million Without Touching a Single Device

August 2, 2026
Aave Reserves

Aave Moves to Deprecate 50 Reserves and Exit Six Chains in $98M Cleanup

July 30, 2026
The Fed Held Rates, but Three Officials Voted to Hike. That’s the Signal Crypto Should Watch

The Fed Held Rates, but Three Officials Voted to Hike. That’s the Signal Crypto Should Watch

July 29, 2026

About

AltcoinReporter

AltcoinReporter is an independent crypto news platform built to keep you ahead of the market. We cover everything from Bitcoin and altcoins to DeFi, NFTs, regulation, and emerging blockchain technology.


Our editorial team delivers accurate news, detailed market analysis, and expert insights, with every article written and reviewed by named contributors. We are committed to transparent, independent reporting our readers can trust.

News

  • Altcoins
  • Bitcoin
  • Blockchain
  • DeFi
  • Ethereum
  • NFT

Reviews

  • Exchanges
  • NFT Marketplaces
  • Wallets

Company

  • About Us
  • Advertise
  • Write for Us
  • Contact Us

Disclaimer: AltcoinReporter.com provides cryptocurrency news for informational purposes only, not financial, investment, or legal advice. Crypto markets carry significant risk. Always do your own research and consult a financial advisor before investing. We may earn compensation through affiliate links, ads, and sponsored content, which are clearly labelled. AltcoinReporter is not responsible for any financial losses resulting from information on this site.

  • Cookie Policy
  • Ethics
  • Corrections
  • Editorial Standards
  • Privacy Policy
  • Terms & Conditions

© 2026 AltcoinReporter. All rights reserved.

No Result
View All Result
  • Home
  • News
    • Altcoins
    • Bitcoin
    • Blockchain
    • DeFi
    • Ethereum
    • NFT
  • Press Releases
  • Reviews
    • Exchanges
    • NFT Marketplaces
    • Wallets
  • Market Analysis
  • Contact Us

© 2026 AltcoinReporter. All rights reserved.