A hardware wallet is supposed to be the boring, reliable part of holding Bitcoin. Plug it in, generate a seed, keep the seed offline, sleep well. That premise took a direct hit this summer when Coinkite, maker of the popular Coldcard wallet, confirmed that a firmware bug going back to March 2021 had quietly made thousands of private keys guessable. Attackers drained roughly 1,816 BTC, worth about $116 million at the time, from more than 5,200 addresses in four separate waves between July 30 and August 4, 2026. By mid-September, the incident still ranked as the largest hardware wallet exploit on record, according to blockchain analytics firm TRM Labs.
Coldcard Hack: $116M Bitcoin Theft From RNG Flaw
A hardware wallet is supposed to be the boring, reliable part of holding Bitcoin. Plug it in, generate a seed, keep the seed offline, sleep well. That premise took a direct hit this summer when Coinkite, maker of the popular Coldcard…
shattered.io
Publisher
Sep 17, 2026 at 4:13 AM UTC · Updated 8 saat önce · 17 dk okuma

Entities
bitcoin
Last Updated
8 saat önce
The Coldcard hack lands in a year already crowded with nine-figure crypto losses, but it stands apart from the usual DeFi bridge exploit or exchange breach. Nobody stole a password. Nobody phished a private key. The wallets did exactly what buyers were told they would do: generate a seed phrase offline, on a dedicated device, away from any network. The seed was just never as random as Coinkite claimed. That distinction is why security researchers, self-custody advocates, and now competing wallet makers are treating this as a different kind of warning than a typical hack headline.
Market Context
Bitcoin
BTC
$76,142
+0.74% (24H)
Market Cap
$1.53T
24H Volume
$22.9B
24H High
$77,095
Article Intelligence
Key Entities
Topics
Related Coverage
Sponsored
AdNewsLayer Premium
Unlock deeper intelligence.
Ad-free reading, exclusive research, and real-time onchain insights.
Go Premium
