A hardware wallet is supposed to be the boring, reliable part of holding Bitcoin. Plug it in, generate a seed, keep the seed offline, sleep well. That premise took a direct hit this summer when Coinkite, maker of the popular Coldcard wallet, confirmed that a firmware bug going back to March 2021 had quietly made thousands of private keys guessable. Attackers drained roughly 1,816 BTC, worth about $116 million at the time, from more than 5,200 addresses in four separate waves between July 30 and August 4, 2026. By mid-September, the incident still ranked as the largest hardware wallet exploit on record, according to blockchain analytics firm TRM Labs.
Coldcard Hack: $116M Bitcoin Theft From RNG Flaw
A hardware wallet is supposed to be the boring, reliable part of holding Bitcoin. Plug it in, generate a seed, keep the seed offline, sleep well. That premise took a direct hit this summer when Coinkite, maker of the popular Coldcard…
shattered.io
Publisher
Sep 17, 2026 at 4:13 AM UTC · Updated 1時間前 · 17 分で読める

Entities
bitcoin
Last Updated
1時間前
The Coldcard hack lands in a year already crowded with nine-figure crypto losses, but it stands apart from the usual DeFi bridge exploit or exchange breach. Nobody stole a password. Nobody phished a private key. The wallets did exactly what buyers were told they would do: generate a seed phrase offline, on a dedicated device, away from any network. The seed was just never as random as Coinkite claimed. That distinction is why security researchers, self-custody advocates, and now competing wallet makers are treating this as a different kind of warning than a typical hack headline.
Market Context
Bitcoin
BTC
$76,329
+0.50% (24H)
Market Cap
$1.53T
Circulating Supply
20.1M BTC
24H Volume
$30.8B
24H High
$76,705
Article Intelligence
Key Entities
Topics
Related Coverage
Sponsored
AdNewsLayer Premium
Unlock deeper intelligence.
Ad-free reading, exclusive research, and real-time onchain insights.
Go Premium
