Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Coldcard Wallet Flaw Leads to Major Bitcoin Heist

Coldcard Wallet Flaw Leads to Major Bitcoin Heist

Posted on August 3, 2026 By CWS

A significant security breach has been linked to Coldcard hardware wallets, resulting in an $88.6 million Bitcoin theft. The attack exploited a vulnerability in the random number generator, allowing attackers to deduce private keys without needing direct access to the devices.

Discovery of the Security Breach

Galaxy Research, a digital asset analysis firm, uncovered suspicious activity on July 30. During a swift 41-minute operation, the attackers managed to extract approximately 1,082.65 BTC, valued at $70.2 million, from 1,196 different addresses.

By August 1, further suspicious transactions were identified, increasing the total amount stolen to 1,367.05 BTC, equating to around $88.6 million, across 4,585 addresses. The transaction patterns indicated a single operator for the first two waves, while the third exhibited variations, suggesting the potential involvement of a different attacker or modified tools.

Technical Details of the Exploit

This attack diverges from typical hardware wallet breaches, which often involve phishing or physical access. Instead, it targeted the wallet creation process. The core issue was traced by Block’s Bitcoin Engineering and Security teams to a code modification on March 1, 2021, which disabled the STM32 hardware random number generator in Coldcard’s production setup.

A flaw in the libngu library caused the system to default to a less secure software generator, Yasmarang, seeded from the device’s UID and timer state. This compromised the randomness of seed generation, allowing attackers to recreate potential seed values offline.

Impact and Recommendations

Coinkite, the manufacturer, revealed that the entropy of affected devices dropped significantly, to approximately 40 bits for Mk3 models and around 72 bits for Mk4, Mk5, and Q models, compared to the standard 128 bits expected from a BIP-39 recovery phrase. This decreased randomness enabled attackers to identify wallets holding Bitcoin by cross-referencing with blockchain data.

Devices impacted include Mk2 and Mk3 models with firmware versions 4.0.1 to 4.1.9, and Mk4, Mk5, and Q models with versions before 5.6.0, 5.6.0, and 1.5.0Q, respectively. Coinkite has advised users to update their firmware and generate new seeds.

Emergency firmware updates were released on July 31, but users must generate new seeds and migrate their funds to secure their assets. Experts also recommend using multi-signature setups across different manufacturers to mitigate risks from isolated vendor vulnerabilities.

As the investigation continues, this incident underscores the importance of robust security practices in safeguarding digital assets.

Cyber Security News Tags:Bitcoin, blockchain security, BTC theft, Coinkite, Coldcard, cryptocurrency theft, firmware vulnerability, hardware wallet, random number generator, security flaw

Post navigation

Previous Post: SonicWall Vulnerabilities Exploited in Ransomware Surge
Next Post: AI’s Role in Modern Security Operations Explained

Related Posts

Critical n8n Automation Platform Vulnerability Enables RCE Attacks Critical n8n Automation Platform Vulnerability Enables RCE Attacks Cyber Security News
Microsoft to End Support for Windows Server 2016 and Windows 10 Microsoft to End Support for Windows Server 2016 and Windows 10 Cyber Security News
New Black-Hat AI Tool Used by Hackers to Launch Cyberattacks New Black-Hat AI Tool Used by Hackers to Launch Cyberattacks Cyber Security News
Researchers Hack Google’s Gemini CLI Through Prompt Injections in GitHub Actions Researchers Hack Google’s Gemini CLI Through Prompt Injections in GitHub Actions Cyber Security News
Your Tier 1 Analyst at SOC Team Is Failing at Effective Triage Your Tier 1 Analyst at SOC Team Is Failing at Effective Triage Cyber Security News
WhatsApp Develops Built-In Cloud Backup with Encryption WhatsApp Develops Built-In Cloud Backup with Encryption Cyber Security News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Phishing Campaign Exploits Google Branding with Fake Email
  • Intel and AMD Address Over 80 Security Flaws
  • Microsoft Defender Patch Bypass: New Zero-Day Vulnerability
  • Sandworm Exploits Job Interviews to Deploy Malicious VPNs
  • LiteLLM Supply Chain Attack Affects Over 2,500 Organizations

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Phishing Campaign Exploits Google Branding with Fake Email
  • Intel and AMD Address Over 80 Security Flaws
  • Microsoft Defender Patch Bypass: New Zero-Day Vulnerability
  • Sandworm Exploits Job Interviews to Deploy Malicious VPNs
  • LiteLLM Supply Chain Attack Affects Over 2,500 Organizations

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark