$70 Million Bitcoin Drained in 41 Minutes — Coldcard Firmware Flaw to Blame
On July 30, an attacker swept 1,082.65 BTC from 1,196 separate addresses in 41 minutes. At the time, that was worth approximately $70.2 million. According to The Hacker News, Galaxy Research traced the sweep to a firmware flaw in Coldcard — a Bitcoin-only hardware wallet made by Canadian firm Coinkite.
The root cause goes back to March 2021. A firmware integration error meant that when a Coldcard device generated a new wallet seed (the master key that controls all your funds), it used a weak software PRNG (pseudorandom number generator — software that mimics randomness) instead of the dedicated hardware chip designed to produce genuinely unpredictable numbers. The difference matters enormously: the software fallback was seeded from predictable values like the chip's unique ID and internal timer registers, collecting no additional randomness after startup.
Think of it like a combination lock that promises 1,000,000 possible combinations, but only ever generates one of about a thousand. An attacker who knows how the lock was made can try every realistic option without ever touching your device.
Crucially, exposure depends on which firmware was running when you first created your seed — not what you have installed today. Emergency firmware patches were released on July 31, but patching alone does not fix a seed that was already generated under the flawed version.
If you own a Coldcard, check your model and firmware history immediately. If your seed was created on an affected version, generate a new seed on the patched firmware and move your coins to the new wallet. Do not restore the old seed anywhere — the weakness travels with it.
Sources

