---
title: "Coldcard Vulnerability: How Hackers Stole $118 Million in Bitcoin from 'Invulnerable' Wallets"
description: "Hackers stole $118 million in Bitcoin from Coldcard hardware wallets by exploiting an error in random number generation. 🚨 A firmware vulnerability allowed attackers to predict seed phrases and steal funds from thousands of devices. ⚠️"
date: 2026-08-04T00:17:13.000Z
lang: en
url: https://xab.info/en/posts/coldcard-vulnerability-how-hackers-stole-118-million-in-bitcoin
tags: [coldcard, bitcoin, cybersecurity, coinkite, blockchain]
publisher: "XAB.info"
---

# Coldcard Vulnerability: How Hackers Stole $118 Million in Bitcoin from 'Invulnerable' Wallets

![Golden physical Bitcoin coin on gold nuggets — symbol of Coldcard cold wallet vulnerability where $118M was stolen](https://xab.info/media/2026/08/04/uязvimost-v-coldcard-hakery-pohitili-118-mln-bitkoinov/uязvimost-v-coldcard-hakery-pohitili-118-mln-bitkoinov-1.webp)

The global cryptocurrency market has faced a massive cyberattack that has called into question the security of even the most protected hardware solutions. Owners of Coldcard crypto wallets have become victims of a hacking operation that began at the end of last week. Preliminary data suggests that attackers managed to steal Bitcoin worth approximately $118 million from several thousand devices.

### Scale and Timeline of the Attack

According to the analytics agency Galaxy Research, the theft operation was carried out in four stages. The first strike occurred on July 30: in just 41 minutes, hackers emptied 1,196 wallets, stealing 1,082.65 Bitcoin. In total, researchers claim that 5,294 devices were compromised, with the total volume of stolen funds amounting to 1,815 Bitcoin.

It is worth noting that, at this time, this information has not been officially confirmed by either the wallet manufacturer — the Canadian company Coinkite — or by law enforcement agencies. This is also reported by blockonomi.com, a resource specializing in crypto analytics.

### Technical Nature of the Vulnerability

Company Block, conducting its own investigation, identified the root of the problem. Hackers exploited a critical error in the Coldcard wallet firmware related to the generation of random numbers. On July 30, the experts' conclusions were passed to the developers.

The Block report explains that the firmware contains an integration error in the random number generator (RNG). Instead of using the reliable hardware RNG STM32, the system used the deterministic backup generator Yasmarang from MicroPython. This allowed attackers to predict the results of the generation.

### Code Error and Consequences

Representatives of Coinkite admitted that the incident occurred due to an error during a firmware update in March 2021. During the modification of the cryptographic library, the creation of the initial value was accidentally redirected to a weaker software generator rather than the hardware module intended for the device.

This vulnerability allowed hackers to generate possible seed phrases (secret sequences of words) offline. Attackers identified corresponding Bitcoin addresses and compared them with addresses visible in the public blockchain. A match confirmed the correctness of the generated phrase, granting access to private keys and the ability to fully control the funds.

### Which Devices Are at Risk

Coinkite published a warning for users, clearly defining the list of vulnerable firmware versions. Seed phrases generated on the following devices are at risk:

- Mk2 and Mk3 models with firmware versions from 4.0.1 to 4.1.9.

- Mk4 and Mk5 models up to standard version 5.6.0 or Edge version 6.6.0X.

- Q models up to standard version 1.5.0Q or Edge version 6.6.0QX.

At the same time, the company clarified that the vulnerability did not affect TAPSIGNER, OPENDIME, and SATSCARD devices, as they use different codebases. As a precautionary measure, Coinkite destroyed all Coldcard devices with vulnerable firmware that were awaiting shipment in warehouses.