#How Do Hardware Wallets Provide Security?
Hardware wallets serve as the preferred solution for securing cryptocurrencies, promising users that their private keys remain offline and safe from various threats. However, for owners of the Coldcard Mk3 hardware wallet, this security assurance faced a significant breach. An attack on July 30, 2026, led to the theft of 1,082.65 BTC, valued at around $70.2 million, from 1,196 wallets, all within a short span of 41 minutes.
The vulnerability emerged just 30 hours prior, when Coinkite, the manufacturer of Coldcard, disclosed a critical flaw in the wallet's firmware. This situation underscores the risks associated with hardware wallets, which are often perceived as foolproof.
#What Was the Flaw in the Coldcard Mk3?
The core issue resided in the random number generator (RNG) within firmware versions 4.0.1 to 5.0.3 of the Coldcard Mk3. When a hardware wallet generates a recovery seed, it relies on a string of random numbers for security. If the RNG is flawed and produces predictable sequences, the generated seed and, consequently, the private key can also become predictable. This predictability allows an attacker with knowledge of the RNG's weaknesses to calculate the private key without physical access to the device.
Independently, Block's engineering team pinpointed the RNG issue and promptly published their findings on the same day Coinkite released its advisory. However, by that time, the attack had already drained the wallets.
A sharper way to see the markets in just 5 minutes.
Same news, different lens. We cut through the noise and hand you the overlooked ideas and the deeper read the crowd misses. Join 38,000+ investors seeing the markets differently.
#How Did the Attack Unfold?
The efficiency of the operation was astonishing. Completing a sweep of 1,196 wallets within 41 minutes indicates that automation played a critical role. The attackers most likely conducted reconnaissance beforehand and prepared a list of vulnerable addresses. On-chain records revealed that many of these wallets had not been active for an extended period, suggesting they belonged to long-term holders who trusted their Coldcard devices for security.
After commencing the theft, the stolen funds were quickly funneled into fewer wallets, with one address receiving approximately 594 BTC from the operation.
#Why Does Timing Matter in This Breach?
The timing of the attack raises serious concerns. The wallets were drained shortly before Coinkite publicly disclosed the vulnerability. This gap of 30 hours prompts critical questions about possible prior knowledge of the vulnerability, which could imply that the attacker was aware of the flaw before public disclosure. While Coinkite did not accuse anyone of wrongdoing, the fact that the advisory did not address such accusations raises even more questions among security professionals and users.
#What Should Hardware Wallet Users Take Away?
For anyone using a hardware wallet, the key takeaway is clear: firmware updates are crucial. The RNG vulnerability illustrates how deeply a flaw can undermine the key generation process, representing a major risk to your assets. Users must regularly verify the firmware version on their devices and stay informed about any security advisories issued by the manufacturer.
Furthermore, the scale and speed of this theft highlight the sophistication of modern attackers, stressing the importance of vigilance and proactive measures in safeguarding cryptocurrency holdings.
By understanding these vulnerabilities and best practices, you can improve your security and protect your investments in the volatile world of cryptocurrency.