Security

Coldcard Firmware Flaw Drains 1,816 BTC: What Bitcoin Miners Must Know About Hardware Wallet Security

August 4, 2026 · 8 min read

Coldcard Firmware Flaw Drains 1,816 BTC: What Bitcoin Miners Must Know About Hardware Wallet Security

A firmware vulnerability in Coldcard hardware wallets — present since March 2021 — has been exploited to drain over 1,816 BTC (worth approximately $114 million) from more than 5,200 wallets. The attack, which began on July 30, 2026, continues in a fourth wave as of today. For Bitcoin miners storing their mining rewards in cold storage, this is a wake-up call.

The Vulnerability: A Single Wrong Function Call

The root cause traces back to a March 1, 2021 firmware commit in Coldcard's Mk2 and Mk3 devices. When migrating to a new cryptography library, the firmware inadvertently routed seed generation to MicroPython's Yasmarang software randomizer — seeded from the chip's serial number and timer registers — instead of the device's hardware random-number generator (RNG).

Because both functions shared a similar name, the build completed without error. The flawed code shipped in firmware v4.0.0 on March 17, 2021, and remained unnoticed for over five years. The result: seeds generated on these devices have significantly reduced entropy, making them reproducible offline by anyone who can constrain the device's serial number and boot timing.

Block's Bitcoin Engineering and Security teams confirmed that the intended 128-bit security strength was effectively reduced. Later devices (Mk4, Mk5, and Q) added a partial fix reseeding with secure-element entropy, but only 32 bits reach the generator — yielding approximately 72 bits of entropy instead of 128.

The Attack: Four Waves of Coordinated Draining

Galaxy Research tracked the exploit across four distinct attack waves, attributing all to a single sophisticated operator:

Wave 1 (July 30): In approximately 25 minutes, 594 BTC (~$38 million) was drained from roughly 500 dormant addresses. The speed and coordination suggested pre-computed vulnerable keys.

Wave 2-3 (July 31 – August 2): Losses climbed to 1,367 BTC across 4,585 addresses. The attacker evolved tactics, targeting smaller balances and using new collection addresses to evade tracing.

Wave 4 (August 3-4): An additional 448.7 BTC swept from 709 addresses at a rate of 13.8 sweeps per block — approximately 45 times the normal transaction rate. Unlike earlier waves, Monday's transactions used replace-by-fee (RBF), giving some victims a narrow window to rescue their coins by outbidding the attacker in the mempool.

Total estimated losses: approximately 1,816 BTC from 5,200+ addresses, worth roughly $114 million at current prices.

Why This Matters for Bitcoin Miners

Bitcoin miners are among the largest holders of self-custodied BTC. Mining pools distribute block rewards directly to miners' wallets, and many operators — especially those running multi-megawatt mining farms — store accumulated rewards in hardware wallets for security. This exploit directly threatens that storage strategy.

CryptoQuant data shows that Bitcoin transfers below 1 BTC spiked to 39,600 BTC on Friday — the highest daily level since the FTX collapse in November 2022. This surge, just 300 BTC shy of the post-FTX record, indicates that smaller holders and miners are rapidly moving funds away from potentially compromised wallets toward exchanges or alternative custody solutions.

For ASIC miner operators running large-scale operations, the implications are significant. A mining farm generating 10+ BTC per month needs secure, reliable storage. If your Coldcard seed was generated on affected firmware, your entire mining treasury could be at risk — even if the device has been air-gapped and stored in a safe for years.

What to Do If You're Affected

Coinkite (Coldcard's maker) released emergency firmware for every affected model: v4.2.0 for Mk2/Mk3, v5.6.0 for Mk4/Mk5, v1.5.0Q for Q, and v6.6.0X/QX for Edge track devices. However, updating firmware alone does NOT fix existing compromised seeds.

Immediate actions required:

1. Update your Coldcard to the latest firmware immediately
2. Generate a completely new seed on the updated device
3. Create all new wallets derived from the new seed
4. Transfer all funds from old wallets to new addresses
5. Consider adding a strong BIP-39 passphrase (25th word) for additional protection

Safe configurations: Seeds created with at least 50 fair dice rolls through the Add Dice Rolls feature are NOT at risk, as the dice input contributed at least 128 bits of independent entropy. Multisig setups using only unaffected devices remain secure. Coinkite's other products (Tapsigner, Satscard, Opendime) use different codebases and are unaffected.

The Self-Custody Reckoning

This exploit strikes at the core promise of hardware wallets: that offline key generation cannot be compromised remotely. Users who followed best practices — buying directly from the manufacturer, keeping devices air-gapped, verifying firmware integrity — still generated guessable keys. The attack didn't require network access or physical device compromise.

The broader market impact is already visible. Reports indicate some Bitcoin holders are moving funds back to exchanges, treating institutional custody as safer in the short term. Analysts speculate this could accelerate adoption of Bitcoin ETFs and professional custody services — particularly among mining companies that need to manage large BTC treasuries.

For MarsHub clients operating BTC mining operations — whether a single ASIC miner at home or a multi-megawatt mining farm with global hosting — this incident reinforces the importance of layered security. Multisignature setups, hardware diversity, regular seed audits, and professional mining hosting with institutional-grade custody solutions all become critical risk management tools.

Looking Forward: Mining Security in 2026

The Coldcard incident lands on a hardware wallet industry already under scrutiny. Earlier in 2026, thieves stole $282 million through social-engineering attacks targeting hardware wallet users. That attack required tricking victims; the Coldcard flaw is fundamentally different — users who did everything right were still vulnerable.

The mining industry's response will likely accelerate several trends: adoption of multisignature treasury management, diversification across multiple hardware wallet vendors, increased use of institutional custody for mining pool payouts, and more sophisticated monitoring of wallet addresses for unauthorized activity.

At MarsHub, we recommend all mining clients review their cold storage security posture immediately. Our global hosting facilities across Texas, Dubai, and Southeast Asia use institutional-grade custody solutions with multisig requirements and regular security audits — protecting your mining rewards against exactly these types of sophisticated attacks.

MarsHub Mining Security Note: Protecting your mining rewards requires more than just efficient ASIC hardware. MarsHub's hosting services include institutional-grade custody solutions, multisig treasury management, and 24/7 security monitoring across all our global mining facilities. Whether you're mining with a single unit or operating a multi-megawatt farm, our team can help you implement robust security practices.

Disclaimer: This article is for informational purposes only and does not constitute financial or security advice. The vulnerability details are based on publicly available information from Galaxy Research, Block, and Coinkite. Always verify security updates directly with hardware wallet manufacturers.

Coldcard Hardware wallet security Bitcoin self-custody BTC miner Firmware vulnerability

Secure Your Mining Future

Explore our selection of high-efficiency ASIC miners and institutional-grade hosting facilities with enterprise custody solutions.

Related Articles