Hackers drained $86 million in Bitcoin from over 4,500 Coldcard hardware wallets due to a software flaw. The vulnerability allowed attackers to predict security keys, bypassing the device's offline protection. Coinkite has released firmware updates to fix the issue.
Hardware wallet manufacturer Coinkite Inc. has confirmed a critical security vulnerability in its Coldcard devices, which has led to the theft of approximately 1,367 Bitcoin. As of August 3, 2026, the total value of the stolen assets is estimated at $86 million, affecting more than 4,500 user wallets. This incident marks a significant security failure for a product specifically designed to offer offline protection for cryptocurrency holdings.
The vulnerability was located in the random-number generator used by the devices to create 'seed phrases.' A seed phrase acts as the master password for a wallet, allowing users to recover their funds. Because the implementation of this generator was flawed, the resulting keys were predictable rather than truly random. This predictability enabled attackers to reverse-engineer the phrases and gain unauthorized access to user funds, even though the wallets were not connected to the internet.
Reports indicate that the exploitation of these wallets occurred rapidly. Some users have reported losing their entire holdings in a matter of minutes. The total estimated loss rose significantly over the weekend as more affected wallets were identified and confirmed as compromised.
Coinkite has acknowledged the defect and advised that funds protected by seed phrases generated on the affected firmware versions are at risk. In response, the company has released updated firmware to patch the security flaw. Users of Coldcard hardware are encouraged to review the company's official security notices and apply the necessary updates immediately to secure their devices.
This event highlights the risks inherent in cryptographic hardware, where the security of the entire system depends on the quality of the math used to generate passwords. Even with offline, cold-storage designs, any flaw in the initial key generation process can render the physical security features ineffective. The primary monitorable for users and investors in this space remains the verification of security updates and the potential for long-term reputational impact on the manufacturer's brand and future product adoption.
