MobbleOpen in Mobble ⇢
Business · Cryptocurrency · published 2026-08-04 · via Forbes

Coldcard firmware flaw enabled $116 million Bitcoin heist since July 30

A firmware vulnerability in Coldcard devices dating to March 2021 has enabled attackers to steal approximately $116 million in Bitcoin from over 5,200 addresses. The flaw caused the devices to bypass their hardware randomness chip during key generation, using predictable software substitutes instead, making wallet seed phrases enumerable. The incident has been called the worst self-custody loss in Bitcoin history.

Expanded Detail

The vulnerability, embedded in the firmware since March 2021, allowed attackers to exploit a critical flaw in the key generation process. Instead of relying on the device's dedicated hardware randomness chip, the firmware fell back to predictable software-based randomness, making the resulting seed phrases mathematically vulnerable to enumeration.

This security lapse enabled the theft of roughly $116 million in Bitcoin across more than 5,200 distinct wallet addresses. The scale of the loss has led observers to characterize this event as the most severe single incident affecting self-custodied digital assets in the cryptocurrency's history.

Context

This incident could significantly undermine user confidence in hardware wallets, which are often marketed as the most secure method for self-custody. Affected individuals may face irreversible financial loss, while the broader crypto community may reconsider the reliability of firmware updates and hardware randomness guarantees. The event may also prompt stricter regulatory scrutiny or industry-wide audits, though the decentralized nature of Bitcoin means recovery options remain limited for victims.

Expanded detail and Context are AI-generated analysis; the linked article remains the authoritative source.
Read the full article at Forbes →
This summary is Al-enhanced to contain extended analysis and broader social context. The original is {NAME); the linked article is the authoritative source. Original headline: “Coldcard Hack: $116 Million Bitcoin Stolen Via Firmware Flaw.” Browse more stories.