INCIDENT EVIDENCE GRAPH

Coldcard hacked — $70.20M lost

On July 30, 2026, between 01:10 and 01:51 UTC, a critical entropy vulnerability in Coldcard Mk3 hardware wallet firmware (versions 4.0.1–4.1.9) caused the device to use a weak software PRNG instead of the hardware true random number generator during seed generation, resulting in only ~40–72 bits of entropy. Attackers were able to derive the private keys and fully drain 1,196 addresses of 1,082.65 BTC (approximately $70.2 million) within a 41-minute window. The funds were quickly consolidated into 4 addresses and have remained unmoved. Coinkite issued a security advisory about 30 hours later, confirmed the issue, released fixed firmware, and strongly urged affected users to migrate their funds.

Primary evidence

  1. Coldcard hacked — $70.20M lost

中文