Coldcard Hardware Wallet (Coinkite) (2026) — Crypto Hack
ActiveA firmware bug from March 2021 in Coldcard hardware wallets caused weak seed generation (40-72 bits instead of 128), allowing brute-force key recovery without physical access. 1,816 BTC was drained from 5,200+ addresses across 4 waves by 15+ separate attackers.
Summary
A firmware bug from March 2021 in Coldcard hardware wallets caused weak seed generation (40-72 bits instead of 128), allowing brute-force key recovery without physical access. 1,816 BTC was drained from 5,200+ addresses across 4 waves by 15+ separate attackers.
How It Was Compromised — Wallet via Firmware Bug / Weak Seed Generation
Coldcard hardware wallets, manufactured by Coinkite, suffered one of the largest hardware wallet exploits in history due to a firmware bug dating back to March 2021. The bug caused weak seed generation, producing seeds with only 40-72 bits of entropy instead of the intended 128 bits. This allowed attackers to brute-force private key recovery without physical access to the devices. Over July and August 2026, 1,816 BTC (approximately $116-$130 million) was drained from more than 5,200 addresses across four separate waves of attacks. At least 15 separate attackers exploited the vulnerability. The bug went unnoticed for years, highlighting the critical importance of auditing cryptographic implementations in hardware wallets.
Fund Flow & Laundering Analysis
Stolen Bitcoin was distributed across 5,200+ addresses and moved by 15+ separate attackers, making fund recovery and tracing extremely difficult. The distributed nature of the attacks suggests coordination or shared knowledge of the vulnerability among multiple threat actors.