A security flaw affecting Coldcard hardware wallets enabled the theft of approximately 594 BTC, worth nearly $38 million, from around 500 wallets in under 30 minutes in late July 2026. The bug, introduced in firmware version 4.0.1 in March 2021, replaced the hardware random number generator with a weaker software alternative, reducing seed entropy to roughly 40 bits for Mk3 models and 72 bits for Mk4, Mk5, and Q models, well below the 128-bit industry standard. Total losses are estimated at over 1,300 BTC, exceeding $80 million. Coinkite released patched firmware and advises affected users to generate new seed phrases and migrate their funds.
Source: Read the original article

