Security News

Cybersecurity news aggregator

HIGH Vulnerabilities SC Media

Coldcard hardware wallet firmware flaw led to $70 million Bitcoin theft

  • What: A firmware flaw in Coldcard hardware wallets led to a $70 million Bitcoin theft
  • Impact: Users with affected wallets risk losing their cryptocurrency
Read Full Article →

Vulnerability Management Coldcard hardware wallet firmware flaw led to $70 million Bitcoin theft August 3, 2026 Share By SC Staff A firmware flaw in Coldcard hardware wallets, a Bitcoin-only device, has been linked to the draining of 1,196 Bitcoin addresses in just 41 minutes on July 30, resulting in the theft of approximately $70.2 million worth of Bitcoin. The issue stems from a March 2021 firmware integration error that incorrectly routed seed generation, as reported by The Hacker News. The vulnerability, identified by Block and detailed by Galaxy Research, occurred because a deterministic software pseudorandom number generator (PRNG) was used instead of the intended hardware random number generator (RNG) for seed generation. This error allowed an attacker, under specific conditions, to reproduce candidate output streams offline. By checking these candidate seeds against public blockchain data, the attacker could identify and drain vulnerable addresses. Coinkite, the manufacturer of Coldcard, has released emergency firmware updates for all affected models and release tracks. However, installing the new firmware does not repair seeds already exposed by the flaw. Coinkite advises users whose seeds may have been compromised to generate a new seed on the patched firmware and move their funds immediately. Restoring an old seed, even to updated firmware, carries the weakness forward. The extent of the vulnerability depends on the firmware version running when the seed was created, with specific versions of Mk2, Mk3, Mk4, Mk5, and Q models being affected. While no attacker has been publicly named, the pattern of the sweep has been mapped, though it mimics legitimate coin movement. Source: The Hacker News SC Staff Related Vulnerability Management Critical vulnerability in Rails Active Storage could lead to RCE SC Staff August 3, 2026 The vulnerability specifically affects Active Storage versions prior to 7.2.3.2, 8.0.x before 8.0.5.1, and 8.1.x before 8.1.3.1, particularly when the libvips image processing library is in use. Vulnerability Management Adobe fixes critical vulnerabilities in Campaign Classic and Bridge SC Staff August 3, 2026 The critical vulnerability in Adobe Campaign Classic, identified as CVE-2026-48449, stems from incorrect authorization and poses a significant risk for remote code execution. Vulnerability Management Why responsible vulnerability disclosure is now a boardroom issue Kara Sprague August 3, 2026 Organizations need a clear vulnerability disclosure process as AI speeds flaw discovery. Related Events Cybercast State of Vulnerability Management Thu Sep 10 Cybercast Why Mythos is the cybersecurity crisis we need On-Demand Event Get daily email updates SC Media's daily must-read of the most current and pressing daily news Business Email By clicking the Subscribe button below, you agree to SC Media Terms of Use and Privacy Policy . Subscribe Related Terms Bug Buffer Overflow Disassembly You can skip this ad in 5 seconds

Share this article