Coldcard Firmware Flaw Linked to Theft of 1,082 Bitcoin in 41 Minutes
A defect in the firmware of COLDCARD hardware wallets degraded randomness when generating seed phrases and has been linked to coordinated sweeps that drained more than 1,000 Bitcoin in under an hour.
On 30 July 2026 an automated attacker emptied 1,082.65 BTC from 1,196 addresses in only 41 minutes. The operation followed a predictable pattern of rapid, offline seed enumeration made possible by insufficient entropy in seeds created on affected COLDCARD devices from Coinkite.
The vulnerability originated in an integration error introduced in March 2021. Instead of using the hardware RNG of the STM32 microcontroller, certain firmware versions routed seed creation to a deterministic software PRNG seeded solely with the chip’s unique identifier and boot-time registers. No additional entropy was mixed after startup, reducing effective entropy to approximately 40 bits on Mk3 units and 72 bits on Mk4, Mk5 and Q models—far below the 128 bits expected from a standard 12-word BIP39 seed.
Seeds remain vulnerable based on the firmware version present at the moment of creation, not the version running today. Affected ranges include Mk2 and Mk3 devices on versions 4.0.0–4.1.9, Mk4 and Mk5 devices before 5.6.0, and Q devices before 1.5.0Q. Corrected builds were also released in the Edge branches for earlier Mk4/Mk5 and Q hardware.
Coinkite published an emergency firmware release on 31 July 2026 that improves entropy for new seeds. Updating the device does not strengthen an already-generated weak seed; funds must be moved to a freshly created seed after the update.
Users who added manual entropy with dice are considered unaffected only if they performed at least 50 fair, independent, and private rolls. A strong, unique BIP39 passphrase creates a separate wallet and adds a defensive layer but does not replace the need to replace the underlying seed. Multisig setups are safe only when the required quorum does not rely exclusively on keys generated by vulnerable firmware.
Owners of potentially affected addresses are advised to monitor on-chain activity and move funds at the first sign of consolidation or unauthorized sweeps. Once an attacker locates a valid seed, automated draining can occur within minutes.
Related articles
Bitget Loses $351 Million in Record 2026 Crypto Theft After Attackers Forge Internal Transfers
Bitget's hot and warm wallets were drained of approximately $351 million on September 24, marking the largest known single crypto theft of 2026. Attackers did not steal private keys but instead forged internal transfer requests that bypassed approval workflows. The stolen assets spanned at least five blockchains, with the largest portion being roughly 103 million XRP worth about $157 million. Bitget's CEO Gracy Chen attributed the incident to North Korean hackers based on IP patterns, behavioral signatures, and on-chain evidence matching prior operations. The exchange maintains a $464 million user protection fund sufficient to cover all losses, while deposits and trading remain unaffected and only withdrawals are temporarily frozen. The case highlights how process-level compromises can bypass even robust key-management controls in cryptocurrency exchanges.
Address Substitution Attacks Exploit Partial Address Checks in Crypto Wallets
Address poisoning, clipboard hijackers, and supply-chain malware all rely on users verifying only the first and last few characters of long blockchain addresses. Researchers detail real incidents including a May 2024 theft of 1,155 WBTC worth roughly 68 million dollars where an attacker poisoned transaction history after a test transfer. Studies from Carnegie Mellon University show that even security-conscious users miss mismatches in truncated addresses 21 to 38 percent of the time. Existing identicons such as Jazzicon and Blockies can be matched by attackers because they depend on only the first eight hex characters. The team released the open-source Humanized Hash library that renders any address or hash as a 4x4 grid of colored shapes using PBKDF2 stretching, making forgery computationally expensive. Calculations indicate that matching both the visual pattern and edge characters requires tens to millions of GPU-years on current hardware. The library supports multiple languages with identical output and carries an MIT license with a fixed algorithm.
Monero Web Wallet Built on Official monero-wallet-rpc Adds Digest Authentication, Two-Phase Transfers and BigInt Precision
A developer created a non-custodial Monero web wallet that runs entirely on the user's machine and communicates only with a personal monero-wallet-rpc instance. The project retained all key-handling logic inside the official RPC daemon while adding a custom backend, frontend and supporting infrastructure. Eight practical challenges were documented, including HTTP Digest authentication that is tightly coupled to TCP connections and the silent loss of monetary precision caused by JSON.stringify on large numbers. The solution introduced two-phase transaction submission to reduce the risk of broadcast errors and replaced floating-point arithmetic with BigInt to guarantee exact handling of Monero amounts. The resulting implementation demonstrates how to expose a convenient web interface without introducing custodial risk or weakening the security model of the Monero wallet RPC.
Liquid Network Federation Wallet Drained of 4000 BTC in Alleged White-Hat Exploit Exposing L-BTC Minting Flaw
On September 7, the Liquid Network sidechain suffered a major incident where its Federation wallet lost approximately 4000 Bitcoin, worth around $320 million or 2.1 billion RMB, leaving only 200 BTC behind. The funds were moved through the authorized SideSwap settlement platform using PAK keys without any reported key compromise. Liquid officials described the actor as a claimed white-hat hacker intending to return assets for a fee, but security experts point to a critical vulnerability allowing unauthorized L-BTC minting that could bypass the 1:1 Bitcoin backing mechanism. The network has halted all new transactions while federation members work on remediation, affecting major platforms including BTSE, Bitfinex, and BitMEX. This event aligns with a broader 2026 trend where attackers target protocol-level asset issuance rather than individual keys, as seen in recent Coldcard RNG flaws and other incidents totaling $972 million in crypto thefts. The case underscores weaknesses in multi-signature federation validation and cross-chain anchoring that go beyond traditional smart contract bugs.