A five-year-old security flaw in Coldcard hardware wallets enabled the theft of 1,824 BTC, worth approximately $140 million at current prices. On July 30, 2026, 594.5 BTC were drained in twenty-five minutes from roughly 500 addresses, with the tally climbing steadily over the following weeks. The vulnerability, located in the libNgU library, bypassed the hardware random number generator, reducing key entropy to roughly 40 bits instead of the expected 128 bits, making the keys brute-forceable. According to TRM Labs, 87% of the stolen funds, totaling 1,561 BTC, still sit dormant on the thieves’ addresses. The firmware patch released by Coinkite only protects future keys; only users who had enabled a BIP-39 passphrase or migrated to a new seed escaped unscathed.
Source: Read the original article

