S&P 5007,489.72▲0.7% Nasdaq25,373.85▲1.0% Dow52,485.03▲0.5% Russell 2K2,931.34▼0.5% 10-Yr4.75%+8bp VIX15.99−1.10 WTI$86.80▲3.8% Gold$4,098.60▼0.0% EUR/USD1.153▲0.5% BTC$62,930▼2.8% Nikkei61,867▲0.7%
At close · Fri, Jul 31, 2026
Daily Market Updates.

Crypto

HomeCryptoMarket StructureColdcard flaw exploited to drain about $38 million in…

Coldcard flaw exploited to drain about $38 million in bitcoin

The theft moved roughly 594 BTC across about 500 single-signature wallets in under 30 minutes, then consolidated most of the funds into a single address that has not moved.

CoinDesk reports that an attacker exploited a key generation randomness bug in some Coldcard hardware wallets to steal roughly 594 bitcoin, valued at about $38 million, from around 500 single-signature wallets in under 30 minutes.

The issue was introduced in Coldcard firmware 4.0.0 in March 2021. According to CoinDesk, affected devices skipped their hardware randomness generator and instead used a predictable software-based key generation method seeded by nonsecret chip data, so the wallets could be drained despite seeds being intended to be drawn from an effectively unguessable random pool.

CoinDesk said the sweep occurred between 01:31 and 01:56 UTC on Friday, moving 1,324 bitcoin chunks across 500 transactions within a three-block window. It also noted that 562 BTC was then consolidated into a single address that has not moved, and that drained wallets were dormant for years, spanning holdings from 2021 to 2026.

CoinDesk added that Coinkite warned users who created seeds on Mk3 devices running firmware 4.0.1 or later, while saying Mk4, Q, and Mk5 appear unaffected so far. The outlet also reported that the theft has had little visible impact on bitcoin’s market price.

Latest closeBitcoin $62,929.67 ▼2.8%

More like this

Sources

Get the close, explained.

One email every trading day: what moved, why it moved, and what's on deck tomorrow. Read in 3 minutes.

Free. Unsubscribe anytime.