A Five-Year-Old Firmware Bug Just Cost Bitcoin Holders $116 Million
Cybersecurity

A Five-Year-Old Firmware Bug Just Cost Bitcoin Holders $116 Million

A 2021 build error in Coldcard hardware wallet firmware silently weakened seed generation to as little as 40 bits, letting attackers brute-force wallets that were never physically touched.

PublishedAugust 8, 2026
Read time5 min read
Share

What actually broke

Coldcard wallets are supposed to draw entropy for seed generation from a dedicated hardware random number generator, the component that is the entire reason to trust a hardware wallet over a software one. A build configuration error introduced in firmware version 4.0.1, released in March 2021, caused the hardware source to be silently bypassed in favor of a weaker software-based generator. Devices kept working normally and gave no indication anything was wrong.

The practical effect was catastrophic. Researchers who analyzed the flaw found it reduced effective key strength from a designed 128 bits down to as little as 40 bits on older devices, a gap large enough to make brute-forcing private keys computationally feasible rather than theoretical. Because the weakness lived in how the seed itself was generated, no amount of physical device security protected the funds. The vault was solid. The key inside it was guessable.

How the theft unfolded

According to blockchain intelligence firm TRM Labs, the theft happened in four distinct waves beginning July 30, 2026. The first wave alone moved roughly 594 BTC, worth about $38 million at the time, out of roughly 500 wallets within 25 minutes, consolidated into a single attacker-controlled address. A separate wave swept 1,082 BTC from 1,196 wallets in just 41 minutes. Over more than 5,200 affected addresses, attackers moved a combined 1,816 BTC, worth approximately $116 million.

TRM Labs declined to attribute the theft to a single group, noting that transaction construction differed meaningfully across the four waves, suggesting more than one attacker independently discovered and exploited the same weakness. Laundering patterns looked exploratory rather than professional, which points to opportunistic actors racing each other to drain wallets rather than one coordinated operation. The hack ranks as the third-largest crypto theft of 2026, in a year that has already seen more than $1.2 billion stolen across 276 separate incidents.

Coinkite's response, and why it is not enough

Coinkite published an advisory acknowledging the flaw and updated it over the following days, urging every affected user to update firmware and migrate to a newly generated seed phrase. That guidance is necessary but incomplete: a firmware update stops new wallets from inheriting the weak randomness, but it does nothing to protect a seed that was already generated on a vulnerable version and never moved. Anyone holding funds on an affected Coldcard since 2021 needs to treat that seed as already compromised until proven otherwise.

One victim, quoted in reporting on the incident, captured the frustration succinctly: doing everything right in terms of using a hardware wallet, avoiding exchanges, and keeping keys offline still was not enough, because the flaw sat in a single line of vendor code nobody outside the company could see or verify. That is the uncomfortable core of the story for any enterprise relying on a vendor's security claims rather than an independently reproducible audit.

The AI-blame narrative, and why security researchers reject it

Coinkite's CEO attributed the bug's discovery to AI-assisted code review outpacing traditional audits, and warned that any firmware which has ever been public should be assumed to already be under adversarial review by both attackers and defenders. That framing shifts attention toward an inevitability narrative in which AI made everyone's old code newly dangerous, and positions the company as caught up in a systemic shift rather than accountable for a specific engineering lapse that shipped five years ago and stayed live through multiple subsequent firmware releases without being caught.

Security specialists pushed back hard on that framing. A disabled hardware random number generator is not a subtle logic bug that only a language model could surface; it is exactly the kind of defect a conventional entropy audit is designed to catch, and one that sat undetected in a widely used, security-critical product for five years. Tangem's CTO put it directly: open-source firmware should not be automatically equated with better security, since visibility only helps if someone with the right expertise is actually looking. The AI framing is a convenient story. The actual failure was conventional and preventable, the kind that a scoped, funded audit against the entropy path specifically would have caught in an afternoon rather than five years later, after the funds were already gone. Treating every disclosure as evidence of an unstoppable new threat class lets vendors off the hook for basic engineering discipline that has nothing to do with AI at all.

What this means for enterprise treasury and custody

Any organization holding digital assets in cold storage, whether that is a corporate treasury, a fund, or a custody provider, should treat this incident as a forcing function to ask vendors for real evidence of entropy source verification, not just a product spec sheet claiming hardware-backed randomness. That means requesting the audit reports, understanding the audit's scope and date, and knowing whether the vendor has runtime verification that the hardware RNG path is actually being used rather than silently falling back to software.

It also means building a rotation posture into custody operations rather than treating wallet generation as a one-time event. Ledger's cybersecurity team framed the underlying principle well: key generation must be anchored in hardware with an architecture that cannot silently downgrade to an untrusted software source, and that guarantee has to be verifiable, not assumed. For a CTO evaluating custody vendors, the Coldcard incident is a concrete argument for demanding that verifiability in the procurement conversation, before the funds move, not after a wave of thefts forces the question.

Tagged#news#security#cybersecurity#breach#cisa#ransomware#zero-day#supply-chain#ai-security#cryptocurrency#coldcard#coinkite#hardware-wallet#firmware-vulnerability#digital-asset-custody#random-number-generator#trm-labs