Loading article…
Coldcard breach stole $70 million from ~1,200 wallets on July 30, exposing a firmware seed flaw and prompting urgent migration advice.
Coldcard wallets lost about $70 million in Bitcoin in a 40‑minute attack on July 30, highlighting a firmware bug that made seed generation predictable and forcing owners to create new seeds to protect their holdings【1】.
| At a glance | |
|---|---|
| Amount stolen | $70 million |
| Wallets affected | ~1,200 |
| Vulnerable firmware | Mk3 version 4.0.1 (Mar 2021) |
| Immediate catalyst | Predictable seed bug exploited remotely |
A 2021 firmware change stopped Coldcard’s hardware RNG and fell back to a software generator built from the chip’s serial number and internal clock readings. This limited each device to roughly four billion possible seeds—a space a modern computer can enumerate quickly. Attackers generated candidate seeds, derived the corresponding addresses, and matched them against the public blockchain, draining the highest‑value wallets first. Chainalysis reported $30 million was taken in the first ten minutes, and the sweep continued for about 40 minutes before Coinkite issued its first warning【1】.
Bitcoin’s price slipped below its $60,000 support level after news of the hack, with fears it could breach the $58,000 level seen at the end of June【2】. The incident also sparked concerns that similar vulnerabilities could affect other hardware wallets that import seeds, as the compromised seed remains guessable even after migration to a different device【2】.
Coinkite released firmware that restores proper hardware randomness, but the fix cannot retroactively secure seeds already generated by the flawed firmware. Owners must generate a completely new seed on the updated firmware and migrate funds to the new address. Those who mixed additional entropy—by rolling physical dice during setup—produced seeds outside the attacker’s searchable pool and escaped loss【1】. A strong passphrase adds a layer of protection, though a weak one offers limited defense. Multisig configurations that include keys from unaffected devices also reduce exposure, but a multisig composed solely of vulnerable Coldcards remains at risk【1】.
The Coldcard breach underscores that offline storage protects keys from direct theft but cannot guarantee seed entropy. As long as firmware‑level randomness flaws exist, even “cold” wallets remain vulnerable, prompting a reassessment of hardware‑wallet security practices.
Coverage is mostly measured — 286 of 300 reports stay neutral.
Every Monday — the token unlocks, Fed dates & catalysts set to move crypto and markets this week. So you’re never blindsided.
Free · 3-min read · one-click unsubscribe
AI-assisted synthesis by the TrendWatcher Editorial Desk · sourced from 2 outlets · Aug 2, 2026 · How we report
The CLARITY Act is scheduled for a Senate cloture vote at 2:15 p.m. ET on 15 September 2026. The legislation, which includes provisions for non-decentralized DeFi protocols, requires 60 votes to advance past the debate stage.
Bitcoin open interest dropped by 13.5% as of 15 September 2026 because traders proactively cut leverage to manage risks associated with the upcoming CLARITY Act vote and Federal Reserve rate decision. This reduction in derivatives exposure occurred before the events took place rather than as a result of forced liquidations.
Market analysts are divided on the immediate price direction for Bitcoin, with some technical indicators flagging a negative outlook if the price breaks below $76,500. While the long-term weekly trend remains constructive, the market is currently structured to absorb the outcome of the Federal Reserve decision rather than predict a specific price movement.
Bitcoin is up 22.2% over the 30-day period leading up to 15 September 2026. This performance follows a rally that saw the price move from approximately $63,000 to $81,700 during August.