DATANEWS

Coldcard Firmware Flaw Linked to Nearly $89 Million in Bitcoin Theft

Barron's · 2026-08-04

A vulnerability in certain Coldcard hardware-wallet firmware versions has been linked to bitcoin thefts estimated at nearly $89 million.

Why it matters: Hardware-wallet security fails if key generation is predictable, even when the device itself is never stolen.

A vulnerability in certain Coldcard hardware-wallet firmware versions has been linked to a series of bitcoin thefts estimated at nearly $89 million.

Coldcard devices are designed to generate and protect the recovery phrase that controls a user's bitcoin. The reported software defect weakened the randomness used during that process, potentially making some recovery phrases predictable enough for sophisticated attackers to reconstruct.

The incident is especially significant because attackers did not need to steal or physically access the hardware wallet. Once a recovery phrase can be predicted, the corresponding private keys can be reproduced elsewhere and used to transfer funds.

Installing updated firmware does not repair a recovery phrase created with affected software. Affected users must create a new recovery phrase using updated software and move funds to addresses controlled by the new seed.

The breach shows that a hardware wallet can isolate private keys from an internet-connected computer, but that protection depends on the device generating keys with sufficient entropy.

Source and attribution →