Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Coldcard Wallet Flaw Leads to Major Bitcoin Heist

Coldcard Wallet Flaw Leads to Major Bitcoin Heist

Posted on August 3, 2026 By CWS

A significant security breach has been linked to Coldcard hardware wallets, resulting in an $88.6 million Bitcoin theft. The attack exploited a vulnerability in the random number generator, allowing attackers to deduce private keys without needing direct access to the devices.

Discovery of the Security Breach

Galaxy Research, a digital asset analysis firm, uncovered suspicious activity on July 30. During a swift 41-minute operation, the attackers managed to extract approximately 1,082.65 BTC, valued at $70.2 million, from 1,196 different addresses.

By August 1, further suspicious transactions were identified, increasing the total amount stolen to 1,367.05 BTC, equating to around $88.6 million, across 4,585 addresses. The transaction patterns indicated a single operator for the first two waves, while the third exhibited variations, suggesting the potential involvement of a different attacker or modified tools.

Technical Details of the Exploit

This attack diverges from typical hardware wallet breaches, which often involve phishing or physical access. Instead, it targeted the wallet creation process. The core issue was traced by Block’s Bitcoin Engineering and Security teams to a code modification on March 1, 2021, which disabled the STM32 hardware random number generator in Coldcard’s production setup.

A flaw in the libngu library caused the system to default to a less secure software generator, Yasmarang, seeded from the device’s UID and timer state. This compromised the randomness of seed generation, allowing attackers to recreate potential seed values offline.

Impact and Recommendations

Coinkite, the manufacturer, revealed that the entropy of affected devices dropped significantly, to approximately 40 bits for Mk3 models and around 72 bits for Mk4, Mk5, and Q models, compared to the standard 128 bits expected from a BIP-39 recovery phrase. This decreased randomness enabled attackers to identify wallets holding Bitcoin by cross-referencing with blockchain data.

Devices impacted include Mk2 and Mk3 models with firmware versions 4.0.1 to 4.1.9, and Mk4, Mk5, and Q models with versions before 5.6.0, 5.6.0, and 1.5.0Q, respectively. Coinkite has advised users to update their firmware and generate new seeds.

Emergency firmware updates were released on July 31, but users must generate new seeds and migrate their funds to secure their assets. Experts also recommend using multi-signature setups across different manufacturers to mitigate risks from isolated vendor vulnerabilities.

As the investigation continues, this incident underscores the importance of robust security practices in safeguarding digital assets.

Cyber Security News Tags:Bitcoin, blockchain security, BTC theft, Coinkite, Coldcard, cryptocurrency theft, firmware vulnerability, hardware wallet, random number generator, security flaw

Post navigation

Previous Post: SonicWall Vulnerabilities Exploited in Ransomware Surge
Next Post: AI’s Role in Modern Security Operations Explained

Related Posts

Vulnerabilities in Preinstalled Android Apps Expose PIN Codes and Allow Command Injection Vulnerabilities in Preinstalled Android Apps Expose PIN Codes and Allow Command Injection Cyber Security News
xHunt APT Hackers Attacking Microsoft Exchange and IIS Web Servers to Deploy Custom Backdoors xHunt APT Hackers Attacking Microsoft Exchange and IIS Web Servers to Deploy Custom Backdoors Cyber Security News
AI-Powered Hackers Breach AWS in Under 10 Minutes AI-Powered Hackers Breach AWS in Under 10 Minutes Cyber Security News
ClayRat Android Malware Steals SMS Messages, Call Logs and Capture Victim Photos ClayRat Android Malware Steals SMS Messages, Call Logs and Capture Victim Photos Cyber Security News
SparkKitty Targets Crypto Users via Photo Scanning SparkKitty Targets Crypto Users via Photo Scanning Cyber Security News
SpyCloud Unveils Top 10 Cybersecurity Predictions Poised to Disrupt Identity Security in 2026 SpyCloud Unveils Top 10 Cybersecurity Predictions Poised to Disrupt Identity Security in 2026 Cyber Security News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • N-able Releases Patch for Exploited N-central Vulnerability
  • AI’s Role in Modern Security Operations Explained
  • Coldcard Wallet Flaw Leads to Major Bitcoin Heist
  • SonicWall Vulnerabilities Exploited in Ransomware Surge
  • Chinese Threat Actor Utilizes Leaked DarkSword for iOS Attacks

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • N-able Releases Patch for Exploited N-central Vulnerability
  • AI’s Role in Modern Security Operations Explained
  • Coldcard Wallet Flaw Leads to Major Bitcoin Heist
  • SonicWall Vulnerabilities Exploited in Ransomware Surge
  • Chinese Threat Actor Utilizes Leaked DarkSword for iOS Attacks

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark