Hackers exploited a firmware flaw in Coldcard hardware wallets, stealing approximately 1,367 BTC, worth nearly $89 million, from 4,585 addresses. The attack began on July 30, 2026, draining roughly 594 BTC in under 30 minutes during the first wave. The vulnerability, introduced in March 2021, affected Coldcard Mk3 firmware versions 4.0.1 through 4.1.9 and stemmed from a bug in the random number generator, which used a software RNG instead of the dedicated hardware generator. Coinkite released a patch on August 1, 2026 and advises affected users to migrate to new seeds immediately.
Source: Read the original article

