Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Flaw in Coldcard Wallet Triggers  Million Bitcoin Heist

Flaw in Coldcard Wallet Triggers $70 Million Bitcoin Heist

Posted on August 1, 2026 By CWS

An alarming vulnerability in Coldcard hardware wallets, manufactured by Canadian company Coinkite, has been linked to a massive Bitcoin theft amounting to $70.2 million. On July 30, a hacker managed to siphon off 1,082.65 BTC from 1,196 addresses in less than an hour, exploiting a firmware flaw identified by Galaxy Research.

Coldcard Firmware Vulnerability

The security breach stems from a firmware integration error dating back to March 2021. This error rerouted seed generation to a deterministic software pseudorandom number generator (PRNG) instead of utilizing the STM32 hardware random number generator (RNG). According to Block’s analysis, an attacker could replicate the potential output streams by determining certain device parameters and comparing derived addresses with public blockchain data.

In response, Coinkite issued an emergency firmware update on July 31 for all impacted models. However, merely updating the firmware does not resolve the compromised seed issue. Users with exposed seeds are advised to generate a new seed using the updated firmware and transfer their funds accordingly.

Technical Insight and Vulnerability Impact

The flaw was traced back to Coldcard’s production configuration, which disabled the MICROPY_HW_ENABLE_RNG macro, inadvertently defaulting to MicroPython’s Yasmarang fallback. This fallback, initialized from the chip’s unique ID and timer registers, lacked fresh entropy post-initialization. Coinkite’s estimates suggest that the effective entropy was significantly lower than required for robust security, particularly on older models.

The exposure risk is linked to the firmware version present during seed creation. Notably, models Mk2 and Mk3 running versions before 4.2.0, and Mk4, Mk5, and Q running older firmware versions, were vulnerable. Coinkite advises users to ensure their seed’s security by employing at least 50 independent dice rolls or migrating to a new seed if any uncertainty exists.

Preventive Measures and Current Status

Coinkite emphasizes that multisig arrangements only offer protection if they are not solely reliant on affected devices. Other products like TAPSIGNER, OPENDIME, and SATSCARD remain unaffected due to different codebases. While the attacker’s identity remains unknown, the transaction pattern discovered by Galaxy Research provides clues to the method but not the perpetrator.

The disclosure of this vulnerability coincides with earlier findings by Coinspect regarding similar weak-PRNG issues in older software wallets. This ongoing saga highlights the critical importance of robust cryptographic security measures in safeguarding digital assets against potential threats.

As the cryptocurrency community grapples with these revelations, the focus remains on reinforcing security protocols and ensuring the integrity of wallet systems to prevent future incidents.

The Hacker News Tags:Bitcoin addresses, Bitcoin theft, Coinkite, Coldcard wallet, cryptocurrency security, cryptographic security, firmware flaw, Galaxy Research, hardware wallet, multisig security, SATSCARD, seed generation, TAPSIGNER, Vulnerability

Post navigation

Previous Post: Top Web Application Firewalls for 2026: Expert Ranking
Next Post: Brinks Home Confirms Major Data Breach Amid Hacker Claims

Related Posts

Malware Hidden in SVG Images Targets Developers Malware Hidden in SVG Images Targets Developers The Hacker News
Go-Based Malware Deploys XMRig Miner on Linux Hosts via Redis Configuration Abuse Go-Based Malware Deploys XMRig Miner on Linux Hosts via Redis Configuration Abuse The Hacker News
Cyber Threats Surrounding FIFA 2026: Key Insights Cyber Threats Surrounding FIFA 2026: Key Insights The Hacker News
New Linux Flaws Allow Password Hash Theft via Core Dumps in Ubuntu, RHEL, Fedora New Linux Flaws Allow Password Hash Theft via Core Dumps in Ubuntu, RHEL, Fedora The Hacker News
Ghost Phishing Unveils Security Gaps in Email Protection Ghost Phishing Unveils Security Gaps in Email Protection The Hacker News
CISA Flags Actively Exploited Digiever NVR Vulnerability Allowing Remote Code Execution CISA Flags Actively Exploited Digiever NVR Vulnerability Allowing Remote Code Execution The Hacker News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Phishing Campaign Exploits Google Branding with Fake Email
  • Intel and AMD Address Over 80 Security Flaws
  • Microsoft Defender Patch Bypass: New Zero-Day Vulnerability
  • Sandworm Exploits Job Interviews to Deploy Malicious VPNs
  • LiteLLM Supply Chain Attack Affects Over 2,500 Organizations

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Phishing Campaign Exploits Google Branding with Fake Email
  • Intel and AMD Address Over 80 Security Flaws
  • Microsoft Defender Patch Bypass: New Zero-Day Vulnerability
  • Sandworm Exploits Job Interviews to Deploy Malicious VPNs
  • LiteLLM Supply Chain Attack Affects Over 2,500 Organizations

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark