BlocktoBlockto
594 Bitcoin Drained From Hundreds of Wallets in Coldcard Key Generation Flaw
TECH

Photo: Illustrative

594 Bitcoin Drained From Hundreds of Wallets in Coldcard Key Generation Flaw

Roughly 594 bitcoin, worth about $38 million, was swept from around 500 separate wallets in a 25-minute window on Friday, traced to a flaw in how Coldcard hardware wallets generated their private keys.

Tristan R.
By Tristan R.

Senior Author · July 31, 2026

2 min
Key takeaways
Roughly 594 bitcoin, worth about $38 million, was swept from around 500 separate wallets in a 25-minute window on Friday, traced to a flaw in how Coldcard hardware wallets generated their private keys.
Attack Unfolded in a Narrow Time Window The theft moved 1,324 chunks of bitcoin across 500 transactions within a three-block span between 01:31 and 01:56 UTC.
Of that total, 562 BTC was later consolidated into a single address that has remained untouched since.

Roughly 594 bitcoin, worth about $38 million, was swept from around 500 separate wallets in a 25-minute window on Friday, traced to a flaw in how Coldcard hardware wallets generated their private keys.

Attack Unfolded in a Narrow Time Window

The theft moved 1,324 chunks of bitcoin across 500 transactions within a three-block span between 01:31 and 01:56 UTC. Of that total, 562 BTC was later consolidated into a single address that has remained untouched since. Every affected wallet was single-signature and held more than 0.15 BTC, with many dormant for years and coins dating back as far as 2021.

Randomness Generator Failed Silently

Coldcard, made by Canadian firm Coinkite, is a hardware device that stores bitcoin keys offline. According to a report from Block’s Bitcoin engineering and security teams, a firmware setting caused the device to bypass its built-in hardware randomness generator, while a flawed check only confirmed the setting existed rather than whether it was active. As a result, key generation fell back to a weaker method based on the device’s serial number and clock data, both of which can be guessed or measured by an attacker. Block traced the issue to a code change from March 2021, first shipped in firmware version 4.0.0.

Coinkite Issues Warning, Newer Models Unaffected

Coinkite warned users who created a seed on an Mk3 device running firmware 4.0.1 or later, stating that its Mk4, Q, and Mk5 models appear unaffected based on early analysis. Both companies described their findings as preliminary, with Block noting it published early because exploitation was already underway. The flaw also affected paper wallet keys, seed-splitting masks, and other related functions. Bitcoin traded above $64,000 during early Asian hours, showing little reaction to the breach.

How markets are positioning

Live market reaction

🛢️WTI Crude
+3.4%
Gold
+1.8%
Bitcoin
-1.8%
$DXY
+0.6%

Disclaimer

This content is for informational purposes only and does not constitute financial, investment, or legal advice. Cryptocurrency trading involves risk and may result in financial loss.

Exclusive partner offer

Start trading
with BloFin today

Up to $500 sign-up bonus and zero-fee trading on your first 30 days.

Buy crypto now

You will be redirected to BloFin

Share article

About the author

Tristan R.
Tristan R.

8+ years covering crypto markets, macro, and geopolitics. Previously at Decrypt and CoinDesk. Focused on the intersection of digital assets and traditional finance.

594 Bitcoin Drained From Hundreds of Wallets in Coldcard Key Generation Flaw — Blockto - Blockto