Coldcard Firmware Bug Tied to $114 Million in Bitcoin Losses

AI Market Summary
Disclosure of a Coldcard firmware build error that reduced mnemonic randomness and enabled multi-round exploitation, with observed losses rising to ~$114M, is negative for Bitcoin custody confidence. The news can drive near-term defensive flows as affected users rotate funds, potentially increasing on-chain activity and highlighting operational security risk in self-custody hardware. While not a protocol issue, it may weigh on sentiment toward retail BTC storage practices.
Impact level
● Medium
Affected assets
BTC/USDT-0.24%
AI Insight · BTC/USDTAI Insight
▼ Bearish
Trade now
⚠️ AI-generated insights are based on news content and are provided for informational purposes only. They do not constitute investment advice or represent the views of BingX. Investing involves risk. Please trade responsibly.
Coinkite, the maker of Coldcard Bitcoin hardware wallets, said in a late-July 2026 disclosure that a firmware build error introduced in March 2021 led some devices to generate recovery mnemonics from a narrower set of possibilities, weakening private-key randomness. Researchers at Galaxy Research reported that the flaw was exploited in multiple waves. Observed Bitcoin losses rose from about $88 million to nearly $114 million over several days. After researchers warned that additional vulnerable addresses could still be attacked, many Coldcard users moved their funds. Coldcard is a Bitcoin-only wallet that supports offline signing via microSD card, with optional QR code functionality. First launched in 2017, it has been widely viewed as one of the more security-focused Bitcoin hardware wallets.