
Hardware wallets promise protection because they keep signing keys away from internet-connected systems. However, secure hardware still depends on reliable firmware. A Coldcard firmware flaw weakened seed generation and allowed attackers to reconstruct vulnerable wallet seeds.
The Coldcard firmware flaw introduces an uncomfortable reality for Bitcoin users. Offline storage cannot protect funds when faulty code makes passkeys predictable. Therefore, the breach raises wider questions about trust, testing, and self-custody.
The Coldcard Firmware Flaw Triggered a $70 Million Sweep
On the 30th of July 2026, attackers drained 1,082.65 BTC from 1,196 Bitcoin addresses. Galaxy Research valued the first sweep at approximately $70.2 million. The attackers completed the coordinated movement within about 41 minutes.
However, the first sweep represented only part of the incident. Later reporting identified additional attack waves and raised the confirmed total to at least 1,778.84 BTC.
At the time of the update, the stolen Bitcoin represented approximately $112.7 million. Investigators also linked activity to more than 8,600 addresses. Researchers report different totals because they track separate attack waves and address groups. Nevertheless, every estimate shows a major failure in Bitcoin self-custody.
Why the Coldcard Firmware Flaw Made Seeds Guessable
A March 2021 firmware release introduced the problem. An integration error redirected seed generation away from the intended hardware random-number generator. Instead, the affected firmware used MicroPython’s Yasmarang software generator.
Block’s security researchers found that Yasmarang could produce predictable results under certain conditions. Because of this, attackers could narrow possible seed values and reconstruct vulnerable wallets offline. Later Coldcard models added more entropy, but reseeding retained only 32 bits of secure entropy.
Coinkite stressed an important distinction. The hardware random-number generator did not simply fail during normal operation. Instead, a build and linking error caused firmware to select the wrong generation path. Therefore, the Coldcard firmware flaw compromised the process that created each vulnerable wallet’s foundation: its seed.
Why the Coldcard Firmware Flaw Matters and What Comes Next
The breach changes how users should understand cold storage. Offline keys can still become vulnerable when firmware creates them with insufficient randomness. A hardware wallet can isolate keys from networks. However, faulty code can weaken protection before users deposit any funds.
As a result, Coinkite advises affected users to create a new seed with fixed firmware. They must then move funds from wallets created under vulnerable conditions. A firmware update cannot repair an old seed.
In addition, users should also follow Coinkite’s guidance about independent, private dice rolls and passphrases. The company later released security updates for seed generation and described additional safeguards.
Meanwhile, multisignature custody can reduce dependence on one device or manufacturer. Galaxy reported no theft transactions from multisignature wallets within the activity it reviewed.
Ultimately, the incident offers a broader lesson for Bitcoin users. Cold storage does not provide perfect security. Effective protection requires dependable hardware, firmware, randomness, review, and migration procedures.
For affected owners, the priority remains clear: verify exposure, create a fresh seed, and move vulnerable funds promptly.
