XRP $3.12 ▲ 4.8% BTC $114,820 ▲ 1.2% ETH $4,380 ▼ 0.6% RLUSD $1.00 ▲ 0.0% XLM $0.41 ▲ 3.1% Fear & Greed 68 · GreedXRP $3.12 ▲ 4.8% BTC $114,820 ▲ 1.2% ETH $4,380 ▼ 0.6% RLUSD $1.00 ▲ 0.0% XLM $0.41 ▲ 3.1% Fear & Greed 68 · Greed
Home / Learn
● Learn

Coldcard Releases Critical Security Patch Following $130 Million Bitcoin Vulnerability

Hardware wallet maker Coinkite has released emergency firmware updates to patch a seed-generation flaw that exposed Bitcoin holders to theft, with attackers stealing over $130 million before the vulnerability was sealed.

JM
by Jacob Marquez · Learn Desk
Published August 21, 2026 · 3 min read

A Decade-Old Flaw Exposed Millions in Bitcoin

Coinkite, the manufacturer of Coldcard hardware wallets, has released updated firmware versions 5.6.1 and 1.5.1Q following discovery of a critical vulnerability affecting its devices. The flaw, which originated in 2021, allowed attackers to drain Bitcoin from air-gapped Coldcard wallets throughout July and early August 2026. By mid-August, researchers had tracked over $130 million in stolen Bitcoin resulting from the coordinated attacks.

The vulnerability centered on inadequate randomness in the wallet seed generation process. The entropy used to create private keys had been severely compromised—reduced from 128 bits of security down to roughly 40 bits. This weakness made it substantially easier for attackers to guess private keys without requiring physical access to the affected devices. In the initial assault, thieves extracted 594 BTC in approximately 25 minutes from roughly 500 compromised wallets, representing approximately $38 million.

Mapping the Attack and Recovery Efforts

Galaxy Research determined that the attacks appeared highly organized and deliberate. By August 14, investigators had identified over 1,778 BTC stolen across multiple coordinated waves and dozens of smaller incidents, distributed across more than 4,500 addresses. Coinkite suggested that attackers may have leveraged artificial intelligence tools to examine the firmware’s open-source code and identify the flaw.

In response, Coinkite launched an intensive three-week security review that enlisted external security researchers and AI models, including Kimi, to identify additional vulnerabilities. The company credited these external partners with their thorough examination of the systems, noting their sustained scrutiny strengthened the final release.

Strengthened Randomness Requirements and Technical Upgrades

The updated firmware fundamentally restructures how users generate wallet seeds. Coldcard now requires users to provide additional entropy through one of three methods: at least 65 deliberate key presses, 50 dice rolls, or 128 coin flips. The device combines this user-generated randomness with its own internal entropy to create wallet seeds, creating a dual-layer approach to preventing predictability.

Beyond user-controlled randomness, Coinkite implemented substantial technical improvements. The company replaced its Yasmarang backup random number generator with the SHA-256 Hash_DRBG algorithm and deployed new checks designed to identify failures in the hardware’s random number generation. Additional fixes addressed issues in transaction signing, USB data handling, firmware validation, Delta Mode, and wallet backup processes. According to Coinkite, the combined improvements eliminate the conditions that made the original exploit possible.

The incident underscores how even well-established cryptocurrency security tools can harbor vulnerabilities with far-reaching consequences, and emphasizes the importance of regular security audits and rapid response mechanisms in protecting digital assets.

Source: Coinkite, via Decrypt. Not financial advice.

// DISCLAIMER: This article is for informational purposes only and is not financial, investment, or trading advice. Terminalcraft may earn a commission from affiliate links. Crypto is volatile and high-risk. Always do your own research.
JM

Jacob Marquez — Learn Desk

Jacob Marquez is the founder and editor of Terminalcraft, an independent XRP-first crypto news desk. An XRP holder and market watcher since 2016, he started Terminalcraft to deliver fast, factual crypto news without the hype.