A software vulnerability in Coldcard hardware wallets resulted in the theft of a total of 1,778 Bitcoin from over 5,000 wallets. The value of the stolen Bitcoin is estimated to be around $112 million. The breach reportedly began on July 30, 2026, due to a flaw in the firmware of Coldcard devices. Within the first 41 minutes, over 1,000 BTC was withdrawn from more than 1,000 wallets. By mid-August, approximately 1,531 BTC was found in wallets controlled by the attackers. Coinkite issued a security alert on July 30 and distributed a patched firmware the following day. The issue was associated with version 4.0.1 and was said to stem from the way seed phrases were generated. It was noted that the vulnerability may have existed unnoticed for years. Devices affected by the attack included the Mk2, Mk3, Mk4, Q, and Mk5 models. Coinkite recommended that users create a new seed phrase using the patched software to transfer their assets to a new wallet. This incident once again highlighted that security vulnerabilities in hardware wallets can lead to significant losses.
This content is provided for general informational purposes only and doesn't constitute financial, investment, legal, or tax advice. Any events, rewards, online promotions, or related information mentioned herein should not be considered a recommendation, solicitation, or invitation to purchase, sell, trade, or otherwise deal in any crypto assets. Crypto assets are highly volatile and may result in loss. The availability of WEEX services, products, and related events may vary by region. You are responsible for ensuring that your participation is in accordance with applicable local laws and regulations.





























