crypto.news and CryptoBriefing both cover Coldcard's firmware fix but disagree on whether an actual theft of Bitcoin occurred.
crypto.news and CryptoBriefing both cover Coldcard's firmware fix but disagree on whether an actual theft of Bitcoin occurred.
which addressed a flaw in how some versions of its firmware generated wallet seed phrases.
attackers exploited a seed-generation vulnerability that drained approximately 1,816 BTC, worth roughly $114M to $116M, from affected wallets.
What would settle it: On-chain transaction records showing outflows from affected Coldcard wallet addresses, or a company statement confirming or denying stolen funds.
Coldcard said in an Aug. 20 post that the latest release followed three weeks of review after its July 31 emergency fix, which addressed a flaw in how some versions of its firmware generated wallet seed phrases.
Attackers began exploiting the weakness on July 30, 2026. Coinkite responded the next day with an urgent hotfix on July 31, but the damage was already substantial.
What would settle it: A public incident report or security disclosure from Coinkite detailing whether active exploitation occurred between July 30 and July 31, 2026.
Treat the firmware versions, the entropy fix, and the migration advice as established; do not treat the $114M/1,816 BTC theft figure as confirmed until Coinkite or on-chain data verifies it.
Treat the firmware versions, the entropy fix, and the migration advice as established; do not treat the $114M/1,816 BTC theft figure as confirmed until Coinkite or on-chain data verifies it.
We measure how many people read this site. That is all it is used for — there is no ad network, no advertising cookie, and nothing sold to anyone. Decline and the site works exactly the same. What we collect