$38M in Bitcoin Stolen: Coldcard Wallets Hacked via Seed Flaw
July 31, 2026
A sophisticated attack exploited a seed-generation flaw in certain Coldcard models, draining roughly 594 BTC (about $38 million) from around 500 single-signature wallets in under 30 minutes on July 31, 2026, underscoring the risk posed by weak entropy in seed creation.
Coldcard advisories warn that seeds generated on Mk3 after firmware 4.0.1, and seeds from Mk4, Q, and Mk5 prior to a fixed firmware release, were at risk, while wallets secured with strong BIP-39 passphrases or dice-generated seeds faced mitigations.
Coinkite recommends affected users regenerate seeds on an unaffected device, verify backups and addresses, perform a small test transaction, and then migrate remaining funds, while monitoring for a formal technical review.
Investigation points to a development oversight: the final build used a fallback RNG instead of the hardware RNG, with a fix later and a build-path validation now being emphasized.
Experts note that the breach primarily hit single-signature wallets, where a compromised seed can control funds without a second authorization, and multisig setups mitigate such risk by requiring multiple keys.
Analysts and observers discuss possible AI-assisted tools aiding attackers, with theories that entropy weaknesses or limited seed paths could help brute-force or identify vulnerable wallets, though concrete links remain under review.
The reporting draws on The Block and other analyses, with caveats about independence and ongoing disclosures as investigations continue.
The incident reinforces a defense-in-depth approach: use multi-vendor multisig, diversified entropy sources, and avoid reliance on a single device or vendor for self-custody security.
Public disclosures describe ongoing drains and wide impact, focusing on why the issue was missed during reviews and how it affects single-signature wallets created without dice rolls or strong BIP-39 passphrases.
While early findings center on single-signature wallets, researchers consider the possibility of targeted exploitation or broader entropy flaws, with partial drains leaving some funds at risk.
An AI-assisted analysis has been suggested as a path attackers may have taken to identify the flaw by reviewing code, with internal reviews reportedly missing the issue weeks earlier.
On-chain movement shows roughly 1,000 BTC moved in relation to the vulnerability, indicating active exploitation and ongoing risk.
Summary based on 17 sources
Get a daily email with more Tech stories
Sources

DEV Community • Jul 31, 2026
A Hardware Wallet Can Stay Offline and Still Create a Weak Seed
Bitcoin Magazine • Jul 31, 2026
Coldcard Wallet Flaw Exposes Years Of Bitcoin Seeds After $70M In BTC Stolen
Bitcoin Magazine • Jul 31, 2026
COLDCARD SECURITY RISK: IMMEDIATE ACTION REQUIRED
Cointelegraph
Coldcard Mk3 Warning Amid Unexplained 594 BTC Sweep