Coldcard Firmware Bug Leads to $116M Bitcoin Theft
Key Facts
Amid growing reliance on self-custody solutions for digital assets, a critical security flaw in Coldcard hardware wallets has resulted in massive losses. According to reports, a firmware bug shipped in March 2021 caused devices to skip their dedicated randomness chips, compromising the security of generated private keys. This five-year-old build flag error eventually led to the drainage of $116 million worth of bitcoin from affected users.
Technical analysis reveals that a single line of code instructed the hardware to ignore its hardware-based random number generator, making the resulting keys predictable and vulnerable to theft. Per market data, this incident highlights systemic vulnerabilities within trusted hardware providers, as the exploit allowed attackers to sweep funds from thousands of addresses across multiple waves of activity targeting the Coinkite-manufactured devices.
With real-time price data for Bitcoin currently unavailable, traders are closely monitoring how this breach impacts consumer trust in hardware wallets. On the macro front, recent calendar data showed German inflation rising to 2.8% in July, while the UK interest rate was held at 3.75% on July 30, 2026, factors that may influence broader risk appetite in the crypto sector as the situation unfolds.