Coldcard Security Flaw Leads to Massive Bitcoin Theft
A five year old software bug in Coldcard wallets has allowed hackers to drain over 1,300 BTC from user accounts.

BTCcoinbeat.news
BTC/USD live chart
LIVEA serious security vulnerability in Coldcard hardware wallets has resulted in the theft of over 1,359 BTC. The issue stems from a flaw in the device software that failed to use a true random number generator when creating private keys. Instead, the device relied on a predictable, low entropy fallback that allowed attackers to guess seed phrases with minimal computing power.
The bug originated in March 2021 when the manufacturer, Coinkite, moved toward a proprietary library called libNgU. For over five years, this mistake went unnoticed until hackers began systematically draining funds in late July 2026. While the company has since released a firmware patch, it cannot protect keys that were already generated using the compromised process.
The impact of this exploit has been significant, with thousands of addresses affected and total losses climbing as brute force attacks continue. Security researchers warn that users should move their funds to new, secure addresses immediately. The incident highlights the risks associated with proprietary code in hardware security devices and has prompted a wider investigation into how such a critical failure persisted for years.
Prices update live from CoinMarketCap. Market data, not financial advice.
Market sentiment
Be the first to react
▍Comments (0)
No comments yet. Start the conversation!



