A firmware entropy flaw in Coinkite's Coldcard hardware wallet enabled an attacker to drain 1,196 Bitcoin addresses of approximately $70 million worth of BTC within a single 41-minute sweep on July 30, 2026 This article explores flaw coinkite coldcard. . The theft happened about 30 hours before the vendor issued its public security advisory.
This reduced the effective entropy from the intended 128 bits down to as little as 40-72 bits, depending on the model, making private keys mathematically guessable offline without ever compromising the physical device. Every sweep transaction paid an identical hardcoded fee of 30.0 sat/vB, a 30- to 75-times overpayment relative to that week’s 0.4 to 1.0 sat/vB network median, which researchers view as a strong signature of automated tooling rather than manual fund movement.
Victims predominantly utilized native segwit under BIP-84, accounting for 1,183 out of 1,196 addresses, alongside a smaller group of 7 nested segwit BIP-49 addresses and 6 legacy BIP-44 entries, reflecting a script scanning multiple derivation paths to reuse weak entropy. The largest address, bc1qq85v2c9…cu9r, contains 562.02 BTC, followed by bc1qx76cae2…fhe3 with 398.48 BTC, bc1q8jy96fe…tp3q with 89.62 BTC, and bc1qnk4zh9q…fecp0 holding 32.45 BTC that remains unspent as of the latest tracking. Coinkite is urging businesses to take advantage of ANY.RUN’s SOC investigation tools to cut through blind spots and contain threats earlier, reducing response costs and minimizing business disruption.












