Coinkite, the Toronto-based company behind the Coldcard hardware wallet, is refusing to quantify the Bitcoin losses from a critical firmware vulnerability. Independent researchers estimate the damage at approximately 2,055 BTC, worth about $130 million, spread across more than 7,300 compromised addresses. The attack, which began on July 30, 2026, drained over 1,082 BTC in just 41 minutes during the initial wave. The flaw originated in the random number generator used during seed phrase creation on Coldcard models Mk2 through Q, affecting firmware versions 4.0.1 through 4.1.9. The company has released a patch in version 4.2.0 and is urging all affected users to generate new seed phrases and transfer their funds immediately.
Source: Read the original article

