Coldcard firmware flaw linked to theft of about 594 BTC from roughly 500 wallets

Coldcard firmware flaw linked to theft of about 594 BTC from roughly 500 wallets

N
News Editor
2026-07-31 10:35:29
An attacker drained about 594 BTC, valued in the report at roughly $38 million, from around 500 separate wallets in a 25-minute window between 01:31 and 01:56 UTC on Thursday, according to Unchained. The theft was traced to a flaw in how Coldcard hardware wallets generated keys. A report from Block’s bitcoin engineering and security teams said a build setting caused some Coinkite devices to derive keys from known values — including a unique identifier, timer state and call history — instead of a random number generator. Block said the same weakness also affected paper wallet private keys, seed-splitting masks and device cloning keys. The exposure depends on the firmware running when a wallet was created, not when the device was purchased, and later firmware updates do not fix seeds that were already generated. Block said the issue affected Coldcard Mk3 devices running v4.0.0, released in 2021, as well as later Mk4, Q and Mk5 models. Coinkite said the impact on Mk4, Mk5 and Q was less severe, but still serious, and advised affected users to migrate to a seed created on an unaffected device.

An attacker swept roughly 594 BTC, worth about $38 million in the report, from around 500 separate wallets between 01:31 and 01:56 UTC on Thursday, according to Unchained. The theft was traced to a flaw in how Coldcard generated wallet keys. Coldcard is an air-gapped hardware wallet built by Toronto-based Coinkite.

About 562 BTC has been consolidated into a single address. A wallet seed is supposed to be random and practically impossible to guess. But Block’s bitcoin engineering and security teams said in a Thursday report that a build setting caused Coinkite devices to build keys from a known unique identifier, timer state and call history instead of using a random number generator.

More than wallet seeds were affected

Block said the same flaw also affected Coldcard paper wallet private keys, seed-splitting masks and device cloning keys.

The firm said exposure depends on the firmware running on a device when the wallet was created, not on when the hardware was bought. A later firmware upgrade does not repair a seed that was already generated. The team also warned that anyone who exported an affected seed into another wallet still holds a weak seed.

Models and firmware in scope

According to Block, the issue affected Coldcard Mk3 devices using firmware v4.0.0, which was released in 2021. It also affected later models, including the Mk4, Q and Mk5.

In its advisory, Coinkite said, "the impact on Mk4, Mk5 and Q is not as severe but is still serious." The company told affected users that a BIP-39 passphrase leaves funds at minimal risk and recommended migrating to a seed generated on an unaffected device.

Traits shared by the drained wallets

Every drained wallet was single-signature and held more than 0.15 BTC. Many had been dormant for years. The coins spanned 2021 to 2026, a range the report said tracks the age of the bug almost exactly.

Disclosure follows another wallet security issue

The disclosure came days after Zilliqa halted native transactions over a flaw in the Ledger signing app it created. That issue allowed attackers to rebuild private keys from data already public on-chain. The report said that weakness had also gone unnoticed since 2019.

This article was originally published by Bit.Fan. For more cryptocurrency news and market insights, visit www.bit.fan.
600

Disclaimer:

The market information, project data, and third-party content displayed on this platform are for industry information sharing only and do not constitute any form of investment advice or return commitment.

Cryptocurrency trading carries high risks. Users should fully assess their risk tolerance and make independent decisions. All profits, losses, and legal responsibilities are borne by the users themselves.