Coldcard Hardware Wallets Hit by $130 Million Bitcoin Theft From a 2021 Firmware Bug
A firmware bug from March 2021 weakened key generation on some Coldcard hardware wallets. Here's what's confirmed, which devices are affected, and what to do if yours is one of them.
What Happened
Starting July 30, 2026, attackers drained bitcoin from thousands of Coldcard hardware wallet addresses across multiple waves. TRM Labs put the confirmed total at roughly 1,816 BTC (about $116 million) from over 5,200 addresses at the time of its analysis, while Halborn's later count put total losses above $130 million across roughly 7,300 addresses as the theft continued across additional waves.
The Root Cause: A 2021 Firmware Bug
The vulnerability traces back to a firmware update released in March 2021. Per Halborn, that update caused Coldcard Mk2 and Mk3 devices running firmware 4.0.1 through 4.1.9 to silently rely on MicroPython's software-based random number generator instead of the device's built-in hardware random number generator when creating private keys. The software generator was seeded only with the device's UID and a hardware timer value at power-on, both predictable by an attacker.
The result: affected keys carried roughly 40 bits of entropy instead of the intended 128, cutting the possible key combinations down to a range that could be brute-forced in about 13 days, without physical access to the device.
Which Devices Are Affected
Coldcard Mk2 and Mk3 units running the flawed firmware versions (or any earlier version, prior to the March 2021 update) are exposed. Coldcard Mk4, Mk5, and Q models use a different implementation with 72-bit entropy and are not affected by this bug.
What Coinkite Has Said
Coinkite, Coldcard's manufacturer, has recommended affected users upgrade to patched firmware and regenerate any private keys created on vulnerable versions. Per Halborn, the company only retains customer purchase records for 120 days, limiting its ability to directly notify everyone who bought a device earlier in the affected window.
What to Do If You Use a Coldcard
If your device is a Mk2 or Mk3 and any seed on it was generated between March 2021 and whenever you last updated firmware, treat that seed as compromised: update to the patched firmware, generate a new seed on the patched version, and move funds to the new addresses. This applies whether or not your specific wallet has been drained yet.
If you're evaluating custody setups more broadly, you can explore how Bitval approaches account security as part of deciding what fits your needs.
This article is for informational purposes only and does not constitute financial or security advice. If you believe your funds may be at risk, consult the hardware wallet manufacturer's official guidance directly.