Loading article…
Coldcard breach stole $70 million from ~1,200 wallets on July 30, exposing a firmware seed flaw and prompting urgent migration advice.
Coldcard wallets lost about $70 million in Bitcoin in a 40‑minute attack on July 30, highlighting a firmware bug that made seed generation predictable and forcing owners to create new seeds to protect their holdings【1】.
| At a glance | |
|---|---|
| Amount stolen | $70 million |
| Wallets affected | ~1,200 |
| Vulnerable firmware | Mk3 version 4.0.1 (Mar 2021) |
| Immediate catalyst | Predictable seed bug exploited remotely |
A 2021 firmware change stopped Coldcard’s hardware RNG and fell back to a software generator built from the chip’s serial number and internal clock readings. This limited each device to roughly four billion possible seeds—a space a modern computer can enumerate quickly. Attackers generated candidate seeds, derived the corresponding addresses, and matched them against the public blockchain, draining the highest‑value wallets first. Chainalysis reported $30 million was taken in the first ten minutes, and the sweep continued for about 40 minutes before Coinkite issued its first warning【1】.
Bitcoin’s price slipped below its $60,000 support level after news of the hack, with fears it could breach the $58,000 level seen at the end of June【2】. The incident also sparked concerns that similar vulnerabilities could affect other hardware wallets that import seeds, as the compromised seed remains guessable even after migration to a different device【2】.
Coinkite released firmware that restores proper hardware randomness, but the fix cannot retroactively secure seeds already generated by the flawed firmware. Owners must generate a completely new seed on the updated firmware and migrate funds to the new address. Those who mixed additional entropy—by rolling physical dice during setup—produced seeds outside the attacker’s searchable pool and escaped loss【1】. A strong passphrase adds a layer of protection, though a weak one offers limited defense. Multisig configurations that include keys from unaffected devices also reduce exposure, but a multisig composed solely of vulnerable Coldcards remains at risk【1】.
The Coldcard breach underscores that offline storage protects keys from direct theft but cannot guarantee seed entropy. As long as firmware‑level randomness flaws exist, even “cold” wallets remain vulnerable, prompting a reassessment of hardware‑wallet security practices.
Coverage is mostly measured — 259 of 300 reports stay neutral.
Every Monday — the token unlocks, Fed dates & catalysts set to move crypto and markets this week. So you’re never blindsided.
Free · 3-min read · one-click unsubscribe
AI-assisted synthesis by the TrendWatcher Editorial Desk · sourced from 2 outlets · Aug 2, 2026 · How we report
Radar Chat is a fork of Signal that adds Bitcoin Lightning payments using the Breez Spark SDK, allowing users to send and receive Bitcoin without running a node.
Approximately 600 Bitcoin, valued at around $40 million, were reported stolen from Coldcard hardware wallets.
Users should generate a new seed, migrate their funds to a new wallet, and avoid using the compromised firmware version.
The price fell in the hours after the attack was disclosed but stayed above the $60,000 support level.
Because Bitcoin’s direct exposure avoids the additional equity dilution and debt risks that can erode returns in leveraged stock structures.