
Instantly create stunning AI-powered web apps and games for your next big project on Asvoria.app. No coding. No waiting. Just launch.
A Hardware Wallet Firmware Flaw Drained About $70 Million in Bitcoin in Under an Hour
July 30, 2026 at 9:40 AMby The Block Whisperer
+1
+0
Nobody touched a device. The keys were reconstructed from public data.
What happened
An attacker swept 1,196 Bitcoin addresses in roughly 41 minutes, taking about 1,082 BTC worth approximately $70.2 million.
Galaxy Research attributed the incident to a firmware defect in Coldcard, the Bitcoin-only hardware wallet made by Canadian manufacturer Coinkite.
The transactions all carried identical fees, contained no change outputs and clustered across a narrow range of blocks, indicating a fully automated sweep rather than manual execution.
The proceeds currently sit in four addresses and have not moved.
The flaw dates back to 2021
According to the analysis, a firmware integration error introduced in March 2021 routed seed generation to a deterministic software pseudorandom number generator instead of the device's hardware random number generator.
That made the resulting seeds reproducible in principle. An attacker able to constrain a handful of device variables could generate candidate seeds offline.
Those candidates were then checked against publicly visible blockchain data and the matching addresses were swept remotely.
Crucially, this required no physical access to any wallet. The attack ran entirely off-device.
Updating firmware is not enough
Coinkite has acknowledged the failure. CEO Rodolfo Novak issued a public apology and said the company accepted full responsibility for the bug and for the review process that missed it.
Emergency firmware has been released for every affected model, with specific minimum versions published for the Mk3, Mk4, Mk5 and Q devices.
The critical detail for holders is that patching alone does not protect existing funds. Private keys derived from a compromised seed remain compromised.
Affected users need to generate an entirely new recovery phrase on corrected firmware and move their coins to it.
The wider security picture in 2026
Galaxy warned that further attacks remain possible against any address generated by a vulnerable Coldcard, and that future attempts need not resemble the pattern seen in this sweep.
The incident lands in an already damaging year. Blockchain security firm Blockaid reported that crypto projects lost more than $1 billion to hacks in the first half of 2026.
Hardware wallets are typically presented as the safest available option for self-custody, which is what makes this case unusual.
The failure was not a user mistake, a phishing link or a compromised exchange. It was a defect in the tool sold to prevent exactly this outcome.
Why this matters
This matters because self-custody is the foundation of the argument that crypto removes counterparty risk.
An entropy failure in a trusted device shifts that risk rather than eliminating it, replacing exchange risk with manufacturer risk.
It also highlights a structural weakness of public blockchains: once a key generation flaw exists, every address ever created by the affected devices is permanently exposed until funds are migrated.
For ordinary holders, the practical lesson is that hardware wallets require active monitoring for firmware advisories, not one-time setup.
The clean takeaway
A firmware defect dating to 2021 allowed an attacker to reconstruct Coldcard wallet seeds offline and sweep roughly $70 million in Bitcoin in 41 minutes. Coinkite has released emergency firmware and accepted responsibility, but patching does not secure existing funds. Affected users must move their coins to newly generated seeds.
Explore more articles like this
Subscribe to Asvoria News to receive all the latest news.
Stay ahead with exclusive press releases and expert insights on Web3 and the Spatial Web. Be the first to hear about Asvoria’s latest innovations, events, and updates. Join us — subscribe today!
Editor’s choice
© 2026 Asvoria. All rights reserved.
Avoria does not endorse or promote investment in any of the tokens or NFT projects featured on this platform.
We accept no responsibility for any losses incurred. Users should conduct their own research and consult with a financial advisor before investing.
For more information about Doing Your Own Research (DYOR), please visit this link.