Vulnerabilities · 42 days ago
The real break is the seed, not the wallet. If Coldcard generated it under the flawed firmware, patching the device now does not change that seed, and the coins tied to it can still be reconstructed later from device state.
Galaxy linked the flaw to a July 30 sweep of 1,196 addresses and 1,082.65 BTC, worth about $70.2 million. The bug came from a March 2021 firmware integration error that sent seed generation to a deterministic software PRNG instead of the hardware RNG. Coinkite released emergency firmware on July 31; Mk3 is fixed in 4.2.0, and the affected paths also include Mk4, Mk5, Q, and Edge releases before the versions named in the source.
That means the safe unit is not the updated wallet but a fresh seed created after the fix. Restoring an old seed carries the weakness forward, so pre-patch seeds remain the lasting blast radius even after the software is updated.
4 sources covering this story
Hackers steal over $130M by exploiting bug in offline hardware wallets | TechCrunch
A security vulnerability in the cryptocurrency hardware wallet Coldcard is allowing hackers to drain the crypto from victims’ wallets.
The Record from Recorded Future
Bitcoin hardware wallet maker destroys some inventory after more than $88 million stolen
The company behind a popular hardware wallet for bitcoin owners was forced to destroy part of its inventory after thieves siphoned more than $88 million from customers through a firmware vulnerability.
Coldcard Users Lose $89m After Bitcoin Wallet Is Hacked
A hacker has drained nearly $89m from Coldcard Bitcoin wallets after exploiting a legacy bug
Coldcard Hardware Wallet Flaw Linked to $70 Million Bitcoin Theft in 41 Minutes
A Coldcard firmware flaw weakens wallet seed generation across five models, while Galaxy links a 1,196-address, $70.2 million sweep to the bug.
Part of the PlainSec briefing for 2026-08-04