41 minutes. $70 million.
It wasn’t the exchange that got hacked. It wasn’t a hot wallet that was stolen. It was Coldcard—the crypto world’s most hardcore hardware wallet. Offline signing. Physical isolation. Air-gapped. The kind that should be unbreakable.
Then it happened.
Fox Business and TechCrunch both reported it. Galaxy Research traced the on-chain addresses. On July 30, 1,196 wallets were swept in 41 minutes. Later it was found there were a second and third wave of attacks. By this Tuesday, total losses have already exceeded $130 million. Forbes, CBC, and The Hacker News all put it on the front page.
The vulnerability dates back to March 2021. Coinkite made an integration mistake in its firmware—seed generation was routed incorrectly to a software pseudo-random number generator, instead of the STM32’s hardware true random number chip. Block’s security team’s plain-English version: the seed can be predicted. No quantum computers needed. No nation-state hackers needed. Just brute force on a normal computer.
The affected models are Mk4, Q, Mk3, Q1, and Edge. Seeds created between March 2021 and May 2023. Coinkite released an emergency firmware patch on July 31. But the patch can’t fix already-generated old seeds—cryptography is cryptography; once seed generation is done, it’s done. The exposed seeds must be rebuilt.
So far, at least 12 different attackers are sweeping these addresses. Galaxy says they’re still monitoring continuously, and the attacks are still running. TRM Labs reports that from 2026 to now, there have been more than 200 crypto-hacking incidents, with total losses of $950 million. Coldcard accounts for 13% of that. The third-largest hacking incident this year.
The most ironic part is the mindset of these victims. They did everything right. Didn’t keep coins on exchanges. Bought a hardware wallet. Pulled the network cable. Signed offline private keys. They thought they were safer than 99% of crypto users. Then they were told that the first line of defense—seeds not being random enough—failed at the firmware level. After that, all the other security measures were just for show.
Coinkite’s official website now has a warning up. All seeds created during the affected time period are now invalid. Move your funds immediately. But on-chain data shows many addresses still haven’t been touched—either the victims haven’t realized it yet, or the private keys are lost and they can’t move anything.
$BTC #Coldcard #Security #Bitcoin