INCIDENT EVIDENCE GRAPH
Coldcard hacked — $70.20M lost
On July 30, 2026, between 01:10 and 01:51 UTC, a critical entropy vulnerability in Coldcard Mk3 hardware wallet firmware (versions 4.0.1–4.1.9) caused the device to use a weak software PRNG instead of the hardware true random number generator during seed generation, resulting in only ~40–72 bits of entropy. Attackers were able to derive the private keys and fully drain 1,196 addresses of 1,082.65 BTC (approximately $70.2 million) within a 41-minute window. The funds were quickly consolidated into 4 addresses and have remained unmoved. Coinkite issued a security advisory about 30 hours later, confirmed the issue, released fixed firmware, and strongly urged affected users to migrate their funds.
- Victim: Coldcard
- Method: 私钥泄漏