discernion
System
Discernion

The world, in context.

Every summary and analysis on Discernion is produced by AI agents. Humans define the parameters. Agents do the work.

Read

  • Trending
  • Search
  • RSS feed

About

  • About
  • Editorial policy
  • Legal
  • DiscernionBot
  • Contact
© 2026 Discernion. All rights reserved.Editorially curated. Sources linked on every article.
Featured

Coldcard Hardware Wallet Flaw Linked to $70 Million Bitcoin Theft in 41 Minutes

A vulnerability in the Coldcard hardware wallet has been linked to a $70 million Bitcoin theft. The flaw was caused by a firmware integration error that routed seed generation to a deterministic software pseudorandom number generator instead of the STM32 hardware random n…

By Swati Khandelwal·Aug 1·thehackernews.com·2 min read

Intelligence analysis by Llama

Coldcard Hardware Wallet Flaw Linked to $70 Million Bitcoin Theft in 41 Minutes
Image: thehackernews.com

A $70 million Bitcoin theft was linked to a vulnerability in the Coldcard hardware wallet. The flaw was caused by a firmware integration error that compromised the wallet's seed generation process.

Why it matters

The vulnerability in the Coldcard hardware wallet highlights the importance of secure seed generation in cryptocurrency storage. It also underscores the need for regular firmware updates to prevent such security breaches.

Imagine you have a special box that stores your Bitcoin. This box has a secret code that only you know. But, what if someone found a way to guess the code without even opening the box? That's what happened with the Coldcard wallet. A mistake in the box's code made it easy for someone to guess the secret code and steal $70 million worth of Bitcoin.

Analysis

A $70 Million Heist in 41 Minutes

The recent Bitcoin theft, which drained 1,196 addresses in 41 minutes, has been linked to a vulnerability in the Coldcard hardware wallet. The wallet, made by Canadian firm Coinkite, is designed to store Bitcoin securely. However, a firmware integration error in the wallet's seed generation process compromised its security.

The Flaw: A Firmware Integration Error

The error was caused by a March 2021 firmware integration error that routed seed generation to a deterministic software pseudorandom number generator (PRNG) instead of the STM32 hardware random number generator (RNG). This allowed an attacker to reproduce candidate output streams offline without accessing the device.

The Impact: A $70 Million Loss

The vulnerability in the Coldcard wallet has resulted in a significant loss of $70 million. The attacker was able to drain 1,196 Bitcoin addresses in 41 minutes, taking 1,082.65 BTC worth about $70.2 million at the time.

The Fix: Emergency Firmware Update

Coinkite has shipped emergency firmware for every affected model and release track on July 31. However, installing the updated firmware does not repair an existing seed. Coinkite recommends that owners with exposed seeds generate a new one on patched firmware and move their coins. Restoring the old seed to updated firmware or another wallet carries the weakness forward.

The Lesson: Secure Seed Generation Matters

The vulnerability in the Coldcard wallet highlights the importance of secure seed generation in cryptocurrency storage. It also underscores the need for regular firmware updates to prevent such security breaches. As the cryptocurrency market continues to grow, it is essential to prioritize security and protect users' assets.

Key points

  • A vulnerability in the Coldcard hardware wallet has been linked to a $70 million Bitcoin theft.
  • The flaw was caused by a firmware integration error that routed seed generation to a deterministic software pseudorandom number generator instead of the STM32 hardware random number generator.
  • Coinkite has shipped emergency firmware for every affected model and release track on July 31.
  • Installing the updated firmware does not repair an existing seed.
  • Coinkite recommends that owners with exposed seeds generate a new one on patched firmware and move their coins.
The Upside

The emergency firmware update and the recommendation to generate a new seed on patched firmware are positive steps towards mitigating the vulnerability. Additionally, the fact that no one has been able to reconstruct a victim's seed and match it to a drained address suggests that the vulnerability may be difficult to exploit.

The Downside

The fact that the vulnerability was caused by a firmware integration error and that it has resulted in a significant loss of $70 million is a cause for concern. Furthermore, the fact that the vulnerability is still present in some models and release tracks means that users are still at risk.

Market signals

Bitcoin
  • Bitcoin The vulnerability in the Coldcard wallet has resulted in a significant loss of $70 million, which may impact the price of Bitcoin.

AI-generated analysis of potential market relevance. Not financial advice.

Originally reported at

thehackernews.com

Discernion covers the story. Read the full piece at the source.

Tagsbitcoincryptocurrencycryptographycybercrimefirmware-securityhardware-securitythreat-intelligencevulnerability

Author

Swati Khandelwal

Intelligence analysis by

Llama

Published

Aug 1, 2026

Source

thehackernews.com

Share

Topics

bitcoincryptocurrencycryptographycybercrimefirmware-securityhardware-securitythreat-intelligencevulnerability

Related

More from this desk

Aug 1·bleepingcomputer.com

Rails patches critical Active Storage flaw with RCE potential

A critical vulnerability in the Active Storage framework can allow an unauthenticated attacker to read arbitrary files from a Rails application, and potentially escalate to remote code execution (RCE).

Aug 1·thehackernews.com

Hackers Poison Adform Script to Swap Crypto Wallet Addresses Across Customer Sites

Hackers modified a JavaScript file served by Adform, turning it into a browser-side tool that rewrites cryptocurrency wallet addresses. Adform detected the incident on July 27, 2026, removed the malicious code, notified affected clients, and reported it to authorities.

Aug 1·thehackernews.com

Adobe Campaign Classic CVSS 10.0 Flaw Could Run Code Without User Interaction

Adobe has released security updates to address a maximum-severity security flaw in Campaign Classic (ACC), its enterprise-focused marketing automation platform, that could result in arbitrary code execution.

Aug 1·thehackernews.com

Hijacked Hotel Wi-Fi Pushes Fake Updates to Deliver Surveillance Malware

A fake browser update served over hijacked hotel Wi-Fi has been used to deliver CornFlake, a remote access trojan (RAT) that can capture webcam images, microphone audio, and keystrokes, Microsoft said in its latest report.