Fnalysis.
Hardware Irony
On July 30, 2026, an attacker drained roughly 594 bitcoin (about $38 million) from nearly 500 Coldcard wallets in a 25-minute sweep, exploiting a firmware bug that had been active since March 2021: instead of using the device's own hardware random number generator, it fell back on a software one, cutting seed security from 128 bits down to as little as 40. By August 2, the stolen total had climbed to roughly 1,367 bitcoin ($88.6 million) across more than 4,500 addresses.
Rodolfo Novak, CEO of Coinkite, the company behind Coldcard, publicly apologized and admitted the company's own review process had failed to catch the bug; the attacker, according to the company itself, used AI to find it first. Because the flaw corrupts the seed itself, updating the firmware isn't enough: anyone with an affected Coldcard has to generate a brand-new recovery phrase and move their funds, since the old one remains permanently compromised.
Source: CoinDesk →Its "cold" storage ran red-hot.