Coldcard Wallets Drained in $116M Exploit
- Security
- Key Compromise

Hackers exploited a randomness flaw in Coldcard firmware 4.0.1 to drain over $116 million in Bitcoin from thousands of wallets. Reports surfaced on August 3 with Galaxy Research mapping a single sweep of roughly $70 million from 1,196 addresses in 41 minutes. Coinkite issued fixes starting early August but could not repair already generated weak seeds.
Incident Details
- Type
- OTHER
- Funds Lost
- $116M
- Status
- Ongoing
Coinkite warned about AI code review failures and released guidance; weak seeds remain unfixable