Category: Crypto General -> Bankruptcy and frauds
Type: article
A firmware bug in Coldcard hardware wallets, introduced in 2021, has enabled attackers to drain over 1,800 BTC (nearly $114 million) from more than 5,200 addresses since July 30, 2026. The flaw made wallet seeds guessable, allowing thieves to brute-force and steal funds without physical access. Coinkite, the manufacturer, has released emergency firmware updates and urged users to move funds to new seeds. A fourth wave of attacks on August 3 used replace-by-fee transactions, giving victims a short window to outbid the thefts in the mempool and recover their coins. The vulnerability affects certain Coldcard models, but seeds created with sufficient dice rolls or strong passphrases may still be safe.
Back