Hardware wallet maker Coinkite is facing the fallout from what is shaping up to be the largest hardware wallet breach on record, after a vulnerability in Coldcard firmware allowed attackers to drain more than 1,778 Bitcoin, worth roughly $112M, from over 5,000 addresses. The attack, which began on July 30, 2026, saw attackers sweep more than 1,000 BTC from over 1,000 addresses in just 41 minutes. The root cause traces back to a firmware update shipped in March 2021, which introduced a flaw in the seed phrase generation process by routing randomness from a hardware RNG to a predictable software-based PRNG. Coinkite released patched firmware on July 31, but affected users must generate entirely new seed phrases on patched devices and move all funds to new wallets immediately, as any seed generated with the vulnerable firmware remains compromised regardless of current firmware version.
Source: Read the original article

