Coinkite Coldcard RNG Bug Drains $38M
- Bitcoin
- Key Compromise
- Security

A broken random number generator in Coldcard firmware allowed an attacker to sweep 594 BTC worth roughly $38 million from around 500 single-signature wallets in a 25-minute window on July 31 2026. The exploit hit between 01:31 and 01:56 UTC. CT labeled it a major key compromise affecting hardware wallet users who had not updated firmware.
Incident Details
- Type
- KEY COMPROMISE
- Funds Lost
- $38M
- Status
- Ongoing
Millions more wallets potentially exposed until users rotate seeds