A serious entropy bug in Coldcard firmware has led to the theft of approximately $70 million in Bitcoin. The bug reduced the intended 128-bit entropy to about 40 bits, allowing attackers to reconstruct seeds. Coinkite, the maker of Coldcard, confirmed that the vulnerability was present in firmware versions from March 2021 to July 2026. Galaxy Research reported that the attacker collected $30 million within the first ten minutes by targeting the largest wallets, with a total of 1,196 drained addresses. Chainalysis is tracking the stolen BTC flows to uncover the liquidation route. Coinkite advises users not only to update but also to generate new seeds and move their funds. Binance CEO CZ emphasized that nothing in crypto security should be considered absolutely safe, echoing previous vulnerabilities with Ledger and Trezor. Analysts point to reputational damage for the hardware wallet industry and the possibility that institutional investors may switch to regulated custody services more quickly. Galaxy Research and Chainalysis expect more clarity on the liquidation route of the stolen BTC within a few weeks.
This content is provided for general informational purposes only and doesn't constitute financial, investment, legal, or tax advice. Any events, rewards, online promotions, or related information mentioned herein should not be considered a recommendation, solicitation, or invitation to purchase, sell, trade, or otherwise deal in any crypto assets. Crypto assets are highly volatile and may result in loss. The availability of WEEX services, products, and related events may vary by region. You are responsible for ensuring that your participation is in accordance with applicable local laws and regulations.





























