A firmware bug introduced in March 2021 by Canadian hardware wallet maker Coinkite quietly weakened the randomness used to generate seed phrases on affected Coldcard devices. Instead of drawing from a robust source of entropy, the flaw redirected seed generation to a software-based pseudorandom number generator. In plain English: the “random” numbers weren’t random enough, making it mathematically feasible for attackers to reconstruct private keys without ever touching the physical device.
How bad did it get
The first major attack wave hit on July 30, 2026. In roughly 25 minutes, approximately 594 BTC, worth around $38 million, disappeared from about 500 addresses. That was just the opening act.
Galaxy Research identified at least three separate waves of attacks. By early August 2026, total losses had climbed to 1,816 BTC, valued between $114 million and $116 million, spread across more than 5,200 compromised addresses. The attacks focused almost exclusively on single-signature wallets, the setup most everyday users run, without the additional security layers that multi-signature configurations provide.
Coinkite’s CEO and the engineering team at Block both confirmed the bug’s existence. Emergency firmware updates were issued, with urgent instructions for affected users to generate fresh seed phrases and move funds immediately. For many, that advice came too late.












