Top StoriesBearish
78
BTC

Coldcard Exploit Drains $70M in Bitcoin, CZ Warns Users

A firmware flaw in Coldcard hardware wallets allowed attackers to guess private keys, draining $70.2M in BTC from 1,196 addresses. CZ urged users to diversify wallets as Coinkite rushed emergency patches.

DecryptDecrypt Staff

Quick Take

1

Coldcard firmware bug since March 2021 weakened seed entropy, enabling key guessing.

2

Galaxy Research identified 1,196 addresses drained for 1,082.65 BTC (~$70.2M) in 41 minutes.

3

CZ warns against blind trust in hardware wallets, advises splitting funds across wallets.

4

Stolen Bitcoin consolidated into few addresses and has not moved; users urged to migrate seeds.

Market Impact Analysis

Bearish

Negative security news could shake confidence in hardware wallets, but overall crypto market reaction is likely muted.

Timeframeshort

Speculation Analysis

Factuality90/100
RumorsVerified
Speculation Trigger70/100
MinimalExtreme FOMO

Key Takeaways

  • A firmware bug in Coldcard wallets since March 2021 weakened seed generation, allowing attackers to guess private keys and drain funds.
  • Galaxy Research traced 1,082.65 BTC (~$70.2 million) stolen from 1,196 addresses within a 41-minute window on July 30.
  • Binance founder CZ warned crypto users that no hardware wallet is foolproof, advising diversification across multiple wallets to mitigate single-point risks.
  • Coinkite shipped emergency firmware fixes, but affected seeds remain compromised; users must migrate to new seeds to secure funds.
Bitcoin Stolen 1,082.65 BTC ~$70.2M value
Addresses Drained 1,196 in 41 minutes
Attack Window 41 minutes on July 30, UTC
Firmware Bug Since March 2021 seed generation flaw

What Happened

A critical flaw in Coldcard hardware wallets led to the theft of over 1,082 Bitcoin, worth roughly $70.2 million. The vulnerability stemmed from a firmware build error dating back to March 2021 that caused affected devices to generate wallet seeds using a software fallback instead of the dedicated hardware random-number generator. This weakened the entropy, making private keys susceptible to guessing. On July 30, an attacker swept funds from 1,196 addresses within a tight 41-minute window. The stolen Bitcoin was consolidated into a handful of addresses and has remained static since. The incident triggered a swift response from manufacturer Coinkite and a public warning from Binance founder Changpeng Zhao.

The Numbers

Galaxy Research mapped the attack, revealing a loss of 1,082.65 BTC—approximately $70.2 million—drained from 1,196 addresses. The exploitation unfolded between 01:10:20 and 01:51:26 UTC on July 30, a narrow 41-minute sprint. Early estimates had pegged the damage at 594 BTC (about $38 million) across 500 wallets, but the full scope nearly doubled upon closer analysis. The consolidated stolen funds have not moved since the initial heist. The underlying firmware bug was introduced in a March 2021 build and remained undetected until the exploit.

Why It Happened

The root cause was a build error in Coldcard’s firmware shipped in March 2021. Instead of using the hardware’s true random-number generator to create seed phrases, the device relied on a predictable software fallback. This drastically reduced the pool of possible private keys, allowing attackers to reverse-engineer or brute-force them. Because the flaw existed in the seed generation process, simply updating the firmware does not fix already compromised seeds. Users who created their wallets with the affected firmware remain exposed until they migrate to a new seed generated on a patched device.

Broader Impact

The exploit underscores a critical reminder: hardware wallets, while more secure than software alternatives, are not infallible. CZ’s warning to avoid blind trust and diversify across multiple wallets reflects a growing sentiment that security requires layered strategies. The incident may prompt other hardware wallet manufacturers to audit their firmware more rigorously, potentially reshaping industry standards for seed generation and user guidance. Coldcard users, in particular, face a wake-up call about the importance of verifying their device’s firmware integrity.

What to Watch Next

  • Whether the stolen 1,082 BTC moves or is laundered—any activity could signal further attack patterns or law enforcement involvement.
  • Coinkite’s long-term response: beyond emergency patches, will they implement more robust safeguards to prevent similar build errors?
  • Other hardware wallet makers may face increased scrutiny, potentially leading to new disclosure practices or security certifications for entropy generation.
Source: Decrypt

This article is for informational purposes only and does not constitute financial advice.

SourceRead the full article on Decrypt
Read full article

Always late to trends?

Join for the latest news, insights & more.

Disclaimer: Bytewit is an independent media outlet that delivers news, research, and data.

© 2026 Bytewit. All Rights Reserved. This article is for informational purposes only.

Read Next

Most Read

⚖️
Top StoriesBearish
58

Minnesota Enforces Crypto ATM Ban After $1M Scam Losses

Minnesota's crypto ATM ban began August 1 following $1 million in scam losses. The law prohibits installing or operating virtual currency kiosks, requiring existing machines deactivated by Saturday and removed by December 31. Tennessee, Georgia, and other states pursue similar restrictive measures.

BTC
90% confidence
Aug 1, 2026, 6:07 PM UTC · Cointelegraph
Coldcard Exploit Drains $70M BTC, CZ Warns Users | Bytewit