Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Coldcard Wallet Flaw Leads to Major Bitcoin Heist

Coldcard Wallet Flaw Leads to Major Bitcoin Heist

Posted on August 3, 2026 By CWS

A significant security breach has been linked to Coldcard hardware wallets, resulting in an $88.6 million Bitcoin theft. The attack exploited a vulnerability in the random number generator, allowing attackers to deduce private keys without needing direct access to the devices.

Discovery of the Security Breach

Galaxy Research, a digital asset analysis firm, uncovered suspicious activity on July 30. During a swift 41-minute operation, the attackers managed to extract approximately 1,082.65 BTC, valued at $70.2 million, from 1,196 different addresses.

By August 1, further suspicious transactions were identified, increasing the total amount stolen to 1,367.05 BTC, equating to around $88.6 million, across 4,585 addresses. The transaction patterns indicated a single operator for the first two waves, while the third exhibited variations, suggesting the potential involvement of a different attacker or modified tools.

Technical Details of the Exploit

This attack diverges from typical hardware wallet breaches, which often involve phishing or physical access. Instead, it targeted the wallet creation process. The core issue was traced by Block’s Bitcoin Engineering and Security teams to a code modification on March 1, 2021, which disabled the STM32 hardware random number generator in Coldcard’s production setup.

A flaw in the libngu library caused the system to default to a less secure software generator, Yasmarang, seeded from the device’s UID and timer state. This compromised the randomness of seed generation, allowing attackers to recreate potential seed values offline.

Impact and Recommendations

Coinkite, the manufacturer, revealed that the entropy of affected devices dropped significantly, to approximately 40 bits for Mk3 models and around 72 bits for Mk4, Mk5, and Q models, compared to the standard 128 bits expected from a BIP-39 recovery phrase. This decreased randomness enabled attackers to identify wallets holding Bitcoin by cross-referencing with blockchain data.

Devices impacted include Mk2 and Mk3 models with firmware versions 4.0.1 to 4.1.9, and Mk4, Mk5, and Q models with versions before 5.6.0, 5.6.0, and 1.5.0Q, respectively. Coinkite has advised users to update their firmware and generate new seeds.

Emergency firmware updates were released on July 31, but users must generate new seeds and migrate their funds to secure their assets. Experts also recommend using multi-signature setups across different manufacturers to mitigate risks from isolated vendor vulnerabilities.

As the investigation continues, this incident underscores the importance of robust security practices in safeguarding digital assets.

Cyber Security News Tags:Bitcoin, blockchain security, BTC theft, Coinkite, Coldcard, cryptocurrency theft, firmware vulnerability, hardware wallet, random number generator, security flaw

Post navigation

Previous Post: SonicWall Vulnerabilities Exploited in Ransomware Surge
Next Post: AI’s Role in Modern Security Operations Explained

Related Posts

New Sicarii RaaS Operation Attacks Exposed RDP Services and Attempts to Exploit Fortinet Devices New Sicarii RaaS Operation Attacks Exposed RDP Services and Attempts to Exploit Fortinet Devices Cyber Security News
New eSIM Hack Let Attackers Clone Profiles and Hijack Phone Identities New eSIM Hack Let Attackers Clone Profiles and Hijack Phone Identities Cyber Security News
CISA Highlights Exploited Langflow Code Injection Flaw CISA Highlights Exploited Langflow Code Injection Flaw Cyber Security News
Threat Actors Abused AV – EDR Evasion Framework In-The-Wild to Deploy Malware Payloads Threat Actors Abused AV – EDR Evasion Framework In-The-Wild to Deploy Malware Payloads Cyber Security News
Curl’s 25-Year Security Flaw Patched in Major Update Curl’s 25-Year Security Flaw Patched in Major Update Cyber Security News
Hackers Allegedly Claim Breach of Mercedes-Benz USA Legal and Customer Data Hackers Allegedly Claim Breach of Mercedes-Benz USA Legal and Customer Data Cyber Security News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Cybercriminals Exploit AI for Sophisticated Scams
  • AI Chatbots’ Vulnerability to Account Hijacking Threats
  • Google Eliminates AI Workflows Over GitHub Security Flaw
  • Keyv npm Package Breach in Major Supply Chain Attack
  • Obsidian Security Secures $85M, Hits $1.1B Valuation

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Cybercriminals Exploit AI for Sophisticated Scams
  • AI Chatbots’ Vulnerability to Account Hijacking Threats
  • Google Eliminates AI Workflows Over GitHub Security Flaw
  • Keyv npm Package Breach in Major Supply Chain Attack
  • Obsidian Security Secures $85M, Hits $1.1B Valuation

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark