Coldcard wallet breach drains $130M in Bitcoin from 7,300 devices

A hardware wallet built to keep Bitcoin offline and out of reach of hackers has instead become the center of one of 2026โs costliest cryptocurrency thefts. The Coldcard wallet breach, tied to a firmware flaw quietly introduced back in March 2021, has drained more than $130 million in Bitcoin from thousands of supposedly secure devices, according to blockchain investigators tracking the fallout.
Key takeaways
- A firmware defect from March 2021 weakened seed phrase randomness on Coldcard hardware wallets, cutting cryptographic key strength from 128 bits to just 40 bits.
- At least 7,300 wallets have been drained across at least three documented attack waves, with total losses now topping $130 million in Bitcoin.
- Blockchain analytics firm TRM Labs has traced the activity to at least 15 distinct threat actors, some likely opportunistic copycats.
- Stolen funds have been routed through privacy tools including Wasabi and Tornado Cash, according to CertiK.
- Coinkite, the maker of Coldcard, has urged affected users to update firmware and migrate to a brand-new seed phrase โ though experts say a full hardware swap is safer.
Firmware Vulnerability at the Root of the Coldcard Wallet Breach
The problem traces back to a single line of code. A firmware build released in March 2021 routed seed phrase generation through a predictable software randomizer instead of the deviceโs dedicated hardware randomness chip, according to security researchers at Block who examined the flaw. That single defect left a limited, guessable pool of possible keys โ something attackers with enough computing power could reproduce entirely offline, without ever touching a victimโs device.
โฆ Continue reading the full article at the original source below.


