Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Coldcard Wallet Flaw Leads to Major Bitcoin Heist

Coldcard Wallet Flaw Leads to Major Bitcoin Heist

Posted on August 3, 2026 By CWS

A significant security breach has been linked to Coldcard hardware wallets, resulting in an $88.6 million Bitcoin theft. The attack exploited a vulnerability in the random number generator, allowing attackers to deduce private keys without needing direct access to the devices.

Discovery of the Security Breach

Galaxy Research, a digital asset analysis firm, uncovered suspicious activity on July 30. During a swift 41-minute operation, the attackers managed to extract approximately 1,082.65 BTC, valued at $70.2 million, from 1,196 different addresses.

By August 1, further suspicious transactions were identified, increasing the total amount stolen to 1,367.05 BTC, equating to around $88.6 million, across 4,585 addresses. The transaction patterns indicated a single operator for the first two waves, while the third exhibited variations, suggesting the potential involvement of a different attacker or modified tools.

Technical Details of the Exploit

This attack diverges from typical hardware wallet breaches, which often involve phishing or physical access. Instead, it targeted the wallet creation process. The core issue was traced by Block’s Bitcoin Engineering and Security teams to a code modification on March 1, 2021, which disabled the STM32 hardware random number generator in Coldcard’s production setup.

A flaw in the libngu library caused the system to default to a less secure software generator, Yasmarang, seeded from the device’s UID and timer state. This compromised the randomness of seed generation, allowing attackers to recreate potential seed values offline.

Impact and Recommendations

Coinkite, the manufacturer, revealed that the entropy of affected devices dropped significantly, to approximately 40 bits for Mk3 models and around 72 bits for Mk4, Mk5, and Q models, compared to the standard 128 bits expected from a BIP-39 recovery phrase. This decreased randomness enabled attackers to identify wallets holding Bitcoin by cross-referencing with blockchain data.

Devices impacted include Mk2 and Mk3 models with firmware versions 4.0.1 to 4.1.9, and Mk4, Mk5, and Q models with versions before 5.6.0, 5.6.0, and 1.5.0Q, respectively. Coinkite has advised users to update their firmware and generate new seeds.

Emergency firmware updates were released on July 31, but users must generate new seeds and migrate their funds to secure their assets. Experts also recommend using multi-signature setups across different manufacturers to mitigate risks from isolated vendor vulnerabilities.

As the investigation continues, this incident underscores the importance of robust security practices in safeguarding digital assets.

Cyber Security News Tags:Bitcoin, blockchain security, BTC theft, Coinkite, Coldcard, cryptocurrency theft, firmware vulnerability, hardware wallet, random number generator, security flaw

Post navigation

Previous Post: SonicWall Vulnerabilities Exploited in Ransomware Surge
Next Post: AI’s Role in Modern Security Operations Explained

Related Posts

New Android Malware ClayRat Mimic as WhatsApp, Google Photos to Attack Users New Android Malware ClayRat Mimic as WhatsApp, Google Photos to Attack Users Cyber Security News
CISA Warns of Apple iOS, iPadOS, and macOS 0-day Vulnerability Exploited in Attacks CISA Warns of Apple iOS, iPadOS, and macOS 0-day Vulnerability Exploited in Attacks Cyber Security News
MessiahGPT AI Tool Fuels Cybercrime with Ransomware MessiahGPT AI Tool Fuels Cybercrime with Ransomware Cyber Security News
Hackers Attacking MongoDB Instances to Delete Database and Add Ransom Note Hackers Attacking MongoDB Instances to Delete Database and Add Ransom Note Cyber Security News
Critical Honeywell CCTV Flaw Exposes User Accounts Critical Honeywell CCTV Flaw Exposes User Accounts Cyber Security News
AI Uncovers Cryptographic Flaws Overlooked by Experts AI Uncovers Cryptographic Flaws Overlooked by Experts Cyber Security News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Top Container Registry Security Tools in 2026
  • Ransomware Developer Sentenced Amid Cybersecurity Alerts
  • Microsoft Resolves Critical Azure AI Foundry Security Issue
  • AI Malware Evolves Hourly to Evade Detection
  • Microsoft Updates Address AI and Cloud Vulnerabilities

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • September 2026
  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Top Container Registry Security Tools in 2026
  • Ransomware Developer Sentenced Amid Cybersecurity Alerts
  • Microsoft Resolves Critical Azure AI Foundry Security Issue
  • AI Malware Evolves Hourly to Evade Detection
  • Microsoft Updates Address AI and Cloud Vulnerabilities

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark