Coldcard Firmware Flaw Is Linked to a $70 Million Bitcoin Sweep
Tech

Coldcard Firmware Flaw Is Linked to a $70 Million Bitcoin Sweep

Ozan
OzanAug 1, 2026 · 2 min read
Share

A firmware flaw in several Coldcard hardware wallets may be connected to one of the fastest large Bitcoin sweeps recorded this year. An unidentified operator moved about 1,082.65 BTC, worth roughly $70.2 million at the time, from 1,196 addresses in just 41 minutes.

The weakness dates to a March 2021 software integration. Code intended to request randomness from the device's hardware generator instead fell back to a deterministic software generator. That mistake could leave recovery seeds with far less entropy than owners expected, making some private keys practical to reconstruct under the right conditions.

Updating firmware is not enough

Coinkite issued an emergency firmware update and warned affected customers to act. Installing the update prevents the same faulty process from being used again, but it cannot make an existing seed more random. A wallet created with weak entropy remains exposed after the device itself is patched.

The company's guidance is to create a fresh seed with corrected firmware and move funds to addresses derived from that new seed. Risk varies by model, firmware version, and how the original seed was generated. Users who supplied their own entropy or added another strong secret may face a different risk profile.

Researchers have mapped the sweep pattern to addresses believed to be affected by the flaw, but no public analysis has yet reconstructed a victim's seed and proved that it controlled a drained address. The connection is serious, but it should still be described as a strong technical link rather than a fully established cause.

The incident is a reminder that an offline wallet can still fail at its most basic task. Air gaps and secure elements cannot protect funds if the seed begins with predictable randomness.

Related Stories