Coldcard Patches $130M Wallet Exploit With Major Security Overhaul
What happened: Coinkite released firmware 5.
What happened: Coinkite released firmware 5.6.1 for its Coldcard hardware wallets after a vulnerability led to the theft of approximately 1,816 BTC (valued at $114M–$130M) from over 5,200 addresses. The flaw, present since March 2021, stemmed from a build configuration error that caused devices to use a weak pseudorandom number generator, drastically reducing seed entropy. Attackers exploited this across four waves starting July 30, 2026. The latest firmware mandates user-supplied randomness and replaces the faulty generator with a more secure alternative.
Why it matters: This incident ranks as the third-largest crypto hack of 2026 and highlights the risks of hardware wallet vulnerabilities, especially those involving entropy and random number generation. Coinkite's rapid response included an emergency hotfix and a comprehensive update, but the fix cannot retroactively secure already-compromised wallets. The episode also underscores the growing role of AI in identifying and exploiting cryptographic weaknesses, as noted by independent researchers.
Source: Decrypt