The Coldcard vulnerability has resulted in nearly $114 million in Bitcoin losses, with some wallet seed phrases lacking randomness
Bitcoin hardware wallet manufacturer Coinkite disclosed in late July 2026 that a firmware build error introduced in March 2021 caused some Coldcard wallets to generate mnemonic phrases from a smaller range, reducing the randomness of user private keys. Galaxy Research researchers stated that the Coldcard vulnerability exploitation occurred in multiple rounds, with observed Bitcoin losses increasing from approximately $88 million to nearly $114 million within a few days.
Researchers warned that other vulnerable addresses may still become targets, prompting many Coldcard users to transfer their Bitcoin. Coldcard is a wallet that only supports Bitcoin and allows for offline signing via microSD cards and optional QR codes. The wallet was launched in 2017 and has long been regarded as one of the Bitcoin hardware wallets focused on security.






